Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 105115
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Bill Kenworthy <billk@iinet.net.au>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 105115 depends on: Show dependency tree
Bug 105115 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-09-06 23:34 0000
From an email announcement to the zebedee list:

After a break of nearly two years there are two new versions of the Zebedee
Secure Tunnel available.
 
Version 2.4.1A contains a very small fix for a possible "denail of service"
attack that can crash Zebedee. The Windows binary package has also been linked
with the latest versions of the zlib and bzip2 libraries. In the case of zlib
this contains security fixes and some possible performace improvements.
 
Version 2.5.3 is the latest "development" version. It contains the same security
bug-fix as 2.4.1A but also fixes other bugs including a long-standing problem
with "reverse mode" tunnelling under Windows. Full details are in the
CHANGES.txt file within the release.
 
Both versions are available via http://winton.org.uk/zebedee or for
http://sourceforge.net/projects/zebedee.
 
    Neil

Reproducible: Always
Steps to Reproduce:
1.
2.
3.




Note: includes a fix for a DOS vulnerability.

------- Comment #1 From Marcelo Goes 2005-09-07 09:06:09 0000 -------
Bumped both versions in cvs, 2.4.1-r1 is x86 stable because of the DOS
vulnerability.
Thanks for reporting!

------- Comment #2 From Sune Kloppenborg Jeppesen 2005-09-09 23:16:13 0000 -------
More info on the other DoS issue here: 
 
http://www.securityfocus.com/archive/1/410157/30/0/ 

------- Comment #3 From Jose Luis Rivero (yoswink) 2005-09-10 10:20:10 0000 -------
zebedee-2.5.3 stable on alpha

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-09-10 23:05:29 0000 -------
Time for GLSA decision on this one. I tend to vote NO. 

------- Comment #5 From Thierry Carrez (RETIRED) 2005-09-11 02:39:30 0000 -------
This is a untrusted-network-facing service so I tend to vote yes.

------- Comment #6 From Sune Kloppenborg Jeppesen 2005-09-11 02:42:01 0000 -------
Well if no auth is necessary I agree with half YES. 

------- Comment #7 From Tavis Ormandy (RETIRED) 2005-09-14 03:15:38 0000 -------
I would vote a weak YES.

------- Comment #8 From Thierry Carrez (RETIRED) 2005-09-14 03:16:47 0000 -------
Let's have one.

------- Comment #9 From Thierry Carrez (RETIRED) 2005-09-14 03:18:17 0000 -------
zebedee is still missing x86 stable keyword.

------- Comment #10 From Chris Gianelloni (RETIRED) 2005-09-15 06:47:38 0000 -------
2.4.1-r1 is stable on x86.  What version needs to be stabilized, then?

------- Comment #11 From Marcelo Goes 2005-09-15 08:47:02 0000 -------
Exactly: 2.4.x is the stable branch and 2.5.x is the development branch. 2.4.1A
(2.4.1-r1) fixes the issue for 2.4.1 and 2.5.3 fixes the issue for 2.5.2.

------- Comment #12 From Thierry Carrez (RETIRED) 2005-09-16 01:11:50 0000 -------
Oops, sorry for the confusion.

------- Comment #13 From Thierry Carrez (RETIRED) 2005-09-19 01:13:41 0000 -------
zebedee depends on zlib so this is just about the DoS.

------- Comment #14 From Thierry Carrez (RETIRED) 2005-09-20 07:00:49 0000 -------
GLSA 200509-14
s390 should mark stable to benefit from GLSA

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug