Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 68375 - Remote DoS through iptables (CAN-2004-0816)
Summary: Remote DoS through iptables (CAN-2004-0816)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All All
: High major (vote)
Assignee: Gentoo Security
URL: http://www.suse.de/de/security/2004_3...
Whiteboard: [linux <2.6.11]
Keywords:
: 71586 (view as bug list)
Depends on:
Blocks:
 
Reported: 2004-10-21 04:20 UTC by Hanno Böck
Modified: 2009-05-03 21:42 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---
plasmaroo: Pending-
koon: Assigned_To? (plasmaroo)


Attachments
Patch (CAN-2004-0816.patch,1.65 KB, patch)
2004-10-21 11:36 UTC, Tim Yamin (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2004-10-21 04:20:18 UTC
http://www.suse.de/de/security/2004_37_kernel.html
contains the details.
CVE is CAN-2004-0816

Although this only affects kernels <2.6.8, we still have ebuilds around where the latest ones are 2.6.7 (e.g. hardened-dev-sources).
Comment 1 Tim Yamin (RETIRED) gentoo-dev 2004-10-21 11:36:04 UTC
Created attachment 42326 [details, diff]
Patch
Comment 2 Tim Yamin (RETIRED) gentoo-dev 2004-10-21 11:37:17 UTC
Ok, all done. The following externally maintained sources remain, adding maintainers to the CC.

hardened-dev-sources - Adding hardened@gentoo.org.
mips-sources - Adding kumba@gentoo.org.
rsbac-dev-sources - Adding kang@gentoo.org.
Comment 3 Guillaume Destuynder (RETIRED) gentoo-dev 2004-10-22 04:57:41 UTC
CAN-2004-0816 => Done for rsbac-dev-sources.
Comment 4 Jeremy Huddleston (RETIRED) gentoo-dev 2004-10-30 02:55:42 UTC
this should be added to a revbump of g-d-s-2.6.7 as well for sparc as it can't use >=2.6.8
Comment 5 Ed Grimm 2004-11-01 01:36:22 UTC
It applies, compiles, and boots without error on hardened-dev-sources-2.6.5-r5.  Personally, I feel that it would at least rate a ~arch ebuild, especially since y'all apparently felt that this was sufficient to pull all hardened-dev-sources ebuilds, rather than merely hard-masking them.
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-11-01 23:56:36 UTC
hardened-dev-sources seems to be patched.

Thanks for patching Joshua but please remember to comment on the bug.
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2004-11-09 08:33:49 UTC
Moving to newly-created kernel-specific category
Comment 8 Thierry Carrez (RETIRED) gentoo-dev 2004-11-09 08:37:13 UTC
I think it's ready for a GLSA, as mips-sources is not required to issue the GLSA.

kumba: please apply patch to mips-sources to benefit from GLSA
Comment 9 Tim Yamin (RETIRED) gentoo-dev 2004-11-09 08:44:47 UTC
This is getting augmented with bug #62524 and bug #68421 for a GLSA...
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-11-17 13:00:17 UTC
*** Bug 71586 has been marked as a duplicate of this bug. ***
Comment 11 George L. Emigh 2004-11-17 13:16:20 UTC
I am seeing indications of this problem in gentoo-dev-sources-2.6.9-r1 and -r4

George
Comment 12 Joshua Kinard gentoo-dev 2004-11-19 18:08:49 UTC
mips-sources updated.
Comment 13 Tim Yamin (RETIRED) gentoo-dev 2005-01-15 14:36:43 UTC
All kernels fixed, closing bug; notifications are being migrated away from GLSAs for kernels, more news coming soon so stay tuned :-]