Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 291357 - <net-analyzer/snort-2.8.5.1 IPv6 TCP/ICMP DoS (CVE-2009-3641)
Summary: <net-analyzer/snort-2.8.5.1 IPv6 TCP/ICMP DoS (CVE-2009-3641)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://vrt-sourcefire.blogspot.com/20...
Whiteboard: B3 [noglsa]
Keywords: STABLEREQ
Depends on:
Blocks:
 
Reported: 2009-10-31 19:18 UTC by Alex Legler (RETIRED)
Modified: 2009-12-18 08:26 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2009-10-31 19:18:31 UTC
CVE-2009-3641 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3641):
  Snort before 2.8.5.1, when the -v option is enabled, allows remote
  attackers to cause a denial of service (application crash) via a
  crafted IPv6 packet that uses the (1) TCP or (2) ICMP protocol.
Comment 1 Jason Wallace 2009-11-01 18:48:48 UTC
I have an ebuild for 2.8.5.1 in testing at the moment. I'll try and post it next week.
Comment 2 Jason Wallace 2009-11-02 17:06:53 UTC
There is a new snort ebuild that resolves this at...

Bug#291604
Comment 3 Patrick Lauer gentoo-dev 2009-11-02 17:24:42 UTC
2.8.5.1 committed.
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2009-11-04 02:33:38 UTC
Arches, please test and mark stable:
=net-analyzer/snort-2.8.5.1
Target keywords : "alpha amd64 ppc ppc64 x86"
Comment 5 Markus Meier gentoo-dev 2009-11-04 11:19:20 UTC
amd64/x86 stable
Comment 6 Tobias Klausmann (RETIRED) gentoo-dev 2009-11-07 22:30:13 UTC
Stable on alpha.
Comment 7 Brent Baude (RETIRED) gentoo-dev 2009-11-17 15:46:31 UTC
ppc64 done
Comment 8 Joe Jezak (RETIRED) gentoo-dev 2009-11-26 13:43:36 UTC
Marked ppc stable.
Comment 9 Stefan Behte (RETIRED) gentoo-dev Security 2009-12-18 02:05:02 UTC
GLSA vote: no.
Comment 10 Pierre-Yves Rofes (RETIRED) gentoo-dev 2009-12-18 08:26:47 UTC
NO too, closing.