Bug 74384 - Linux kernel IGMP vulnerabilities (CAN-2004-1137)
|
Bug#:
74384
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: All
|
Status: RESOLVED
|
Severity: normal
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: christian.korff@gmail.com
|
|
Component: Kernel
|
|
|
URL:
http://isec.pl/vulnerabilities/isec-0018-igmp.txt
|
|
Summary: Linux kernel IGMP vulnerabilities (CAN-2004-1137)
|
|
Keywords:
|
|
Status Whiteboard: [linux <2.6.10]
|
|
Opened: 2004-12-14 07:31 0000
|
*** Bug 73210 has been marked as a duplicate of this bug. ***
The BK changesets in comment #1 appear to be for isec-0019-scm
Yes, you're right... I was confused by those CMSG/IGMP stuff. Latest patch by
Chris Wright follows.
Any fixed version coming to portage?
Ah, sorry. gentoo-dev-sources-2.6.9-r10 has the fix, but is masked. May I
suggest unmasking?
sparc-sources 2.4.28-r2 are patched
Doesn't affect <= 2.4.21...
Patched in ~x86 hardened-sources-2.4.28-r1
Ok, all patched - the following externally maintained sources still need
patching:
gentoo-dev-sources-2.6.7 -- Adding dsd...
hppa(-dev)-sources -- Adding GMSoft...
mips-sources -- Adding `Kumba...
openmosix-sources -- Adding cluster herd...
pegasos-dev-sources -- Adding dholm...
rsbac(-dev)-sources -- Adding kang...
hardened-dev-sources-r18 fixed
gentoo-dev-sources 2.6.8 (not 2.6.7) is eradicators deal
Sorry, sparc is actually on 2.6.9 and already done
pegasos-dev-sources fixed
2.4 is dropped on hppa and I've added 2.6.10-pa1 which doesn't seems affected
by this problem.
rsbac-dev-sources/rsbac-sources patched
kang: 2.6.10 and 2.4.28-r2 need stabilizing...
Tim Yamin : I'm working on it. Didn't had inet the past weeks due to a big isp
failure.. i just got it back today.
I was able to commit a few things in between ;)
will get that ready before 2005.0 snapshot (luckily isp doesn't fails tomorrow
again ;)