Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 191100 - media-sound/teamspeak2-server-bin < 2.0.24.01 Nulls in tcpquery protocol
Summary: media-sound/teamspeak2-server-bin < 2.0.24.01 Nulls in tcpquery protocol
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-09-02 21:46 UTC by Martin Jackson (RETIRED)
Modified: 2007-10-02 21:31 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Martin Jackson (RETIRED) gentoo-dev 2007-09-02 21:46:48 UTC
From email to the teamspeak announce list:

Dear TeamSpeak user!

You're receiving this email because you've subscribed to the 
official TeamSpeak newsletter service.

A new version of the TeamSpeak 2 server is now available for 
download. This release deals with several NULL-byte issues in 
the TCP query interface which could cause database corruption.

Because 2.0.24.1 is a security release, it is important that you 
upgrade your TeamSpeak servers as soon as possible. Upgrading from 
any version on Linux, simply involves overwriting your currently 
installed server binary with the updated version. Windows users can 
use the new executable or service installer to get their servers 
up-to-date.

You can grab the new release from our Downloads page.

http://www.teamspeak.com/?page=downloads

A full package will be released soon if no more bugs 
are found.

Do not reply to this message! Any reply to this message will be 
deleted by our system.

Sincerely,
The TeamSpeak Team
Comment 1 Martin Jackson (RETIRED) gentoo-dev 2007-09-02 21:51:56 UTC
I have committed an ebuild for 2.0.24.01 that resolves this issue; it is a hybrid ebuild like the last couple I've done for teamspeak-server.  Since this is a security issue, I'd like to stable the new ebuild as soon as possible so I can remove the vulnerable one from the tree.

Thanks, mjolnir.
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-03 07:53:19 UTC
thanks for the report Martin.
Arches, please test and mark stable media-sound/teamspeak2-server-bin-2.0.24.01.
Target keywords are: "-* amd64 x86"
Comment 3 Christian Faulhammer (RETIRED) gentoo-dev 2007-09-04 06:23:01 UTC
x86 stable
Comment 4 Christoph Mende (RETIRED) gentoo-dev 2007-09-16 16:45:52 UTC
amd64 stable
Comment 5 Christian Faulhammer (RETIRED) gentoo-dev 2007-09-16 17:05:37 UTC
If we stay with that severity level, GLSA vote is now open
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2007-09-21 10:01:41 UTC
ping, please vote.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-09-24 16:35:15 UTC
I tend to vote NO.
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-25 09:41:13 UTC
voting NO.
Comment 9 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-10-02 21:31:20 UTC
no too closing feel free reopen if disagree