Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 84547
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Thierry Carrez (RETIRED) <koon@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
ethereal-0.10.10.ebuild ethereal-0.10.10.ebuild text/plain Aaron Walker (RETIRED) 2005-03-11 10:36 0000 2.45 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 84547 depends on: Show dependency tree
Bug 84547 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-03-08 13:35 0000
Ethereal 0.10.10 is scheduled to be released on Thursday, March 10. It
addresses the following security issues:

  The Etheric dissector was susceptible to a buffer overflow.
  Versions affected: 0.10.7 to 0.10.9
  Fixed in revision: 13176

  The GPRS-LLC dissector could crash if the "ignore cipher bit" option was
enabled.
  Versions affected: 0.10.7 to 0.10.9
  Fixed in revisions: 13386 (further improvements in 13549 and 13571)

  The 3GPP2 A11 dissector was susceptible to a buffer overflow.
  Versions affected: 0.10.3 to 0.10.9
  Fixed in revision: 1357

------- Comment #1 From Thierry Carrez (RETIRED) 2005-03-08 13:39:06 0000 -------
Ccing eldad and dragonheart as recent version bumpers.
This is still confidential, official release of 0.10.10 is Thursday at 3:00PM CST (21:00 UTC).
Will one of you be around to check and commit the new version then ?

------- Comment #2 From Luke Macken (RETIRED) 2005-03-08 16:51:12 0000 -------
public @ http://www.securityfocus.com/archive/1/392659

------- Comment #3 From Sune Kloppenborg Jeppesen 2005-03-09 00:10:25 0000 -------
eldad is away until april -> uncc'ing.

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-03-09 22:20:34 0000 -------
CVE ids assigned:

CAN-2005-0704 Etheric
CAN-2005-0705 GPRS-LLC
CAN-2005-0699 3GPP2 A11 

------- Comment #5 From Sune Kloppenborg Jeppesen 2005-03-10 22:23:07 0000 -------
Another issue popped up so the release date is changed to: March 11 17:00 GMT.

The IAPP dissector is vulnerable to a buffer overflow.
Versions affected: 0.9.1 to 0.9.9

------- Comment #6 From Aaron Walker (RETIRED) 2005-03-11 10:35:35 0000 -------
Daniel, I've stayed up long enough waiting... gotta get some sleep.

Good news is I've done all the work for ya (working from a svn snapshot of the 0.10.10 branch from about an hour or two ago).  The only patch in the previous ebuild is no longer required.

Modified ebuild is attached.

------- Comment #7 From Aaron Walker (RETIRED) 2005-03-11 10:36:14 0000 -------
Created an attachment (id=53190) [details]
ethereal-0.10.10.ebuild

------- Comment #8 From Aaron Walker (RETIRED) 2005-03-11 10:41:34 0000 -------
*sigh* nevermind.  Got the announcement in my mailbox right after I pressed
"Commit".

Going to build with the official tarball and make sure everything is still ok.

------- Comment #9 From Aaron Walker (RETIRED) 2005-03-11 11:08:43 0000 -------
In CVS, stable on x86.  Will the CC'd archs please mark stable?

------- Comment #10 From Jan Brinkmann (RETIRED) 2005-03-11 12:08:44 0000 -------
stable on amd64

------- Comment #11 From Bryan Østergaard (RETIRED) 2005-03-11 20:17:54 0000 -------
Stable on alpha.

------- Comment #12 From Michael Hanselmann (hansmi) (RETIRED) 2005-03-12 00:26:18 0000 -------
Stable on ppc.

------- Comment #13 From Markus Rothe 2005-03-12 04:04:04 0000 -------
stable on ppc64

------- Comment #14 From Gustavo Zacarias (RETIRED) 2005-03-12 05:34:13 0000 -------
sparc done.

------- Comment #15 From Luke Macken (RETIRED) 2005-03-12 09:00:10 0000 -------
GLSA 200503-16

ia64, please mark stable to benefit from GLSA.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug