Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 230075 (CVE-2008-2953) - net-p2p/linuxdcpp <1.0.1-r2 Two Remote DoS issues (CVE-2008-2953,CVE-2008-2954)
Summary: net-p2p/linuxdcpp <1.0.1-r2 Two Remote DoS issues (CVE-2008-2953,CVE-2008-2954)
Status: RESOLVED FIXED
Alias: CVE-2008-2953
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/30812/
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-06-29 18:01 UTC by Robert Buchholz (RETIRED)
Modified: 2008-07-06 21:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-06-29 18:01:06 UTC
Secunia:

Description:
A weakness has been reported in DC++, which can be exploited by malicious people to cause a DoS (Denial of Service).

The weakness is caused due to a NULL pointer dereference error when handling partial file list requests and can be exploited to cause the application to crash.

The weakness is reported in versions prior to 0.707 (Unstable).

Solution:
The vendor has released version 0.707 (Unstable).

Provided and/or discovered by:
The vendor credits crise.

Original Advisory:
http://sourceforge.net/project/shownotes.php?release_id=608612&group_id=40287
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-06-29 18:10:05 UTC
Steven Sheehy of linuxdcpp writes:
It does affect linuxdcpp. I have just committed a fix to cvs for this issue. We 
are hoping to release a new version sometime next month.

http://cvs.berlios.de/cgi-bin/viewcvs.cgi/linuxdcpp/linuxdcpp/client/ShareManager.cpp.diff?r1=1.14&r2=1.15&sortby=date
Comment 2 Santiago M. Mola (RETIRED) gentoo-dev 2008-06-29 18:46:57 UTC
Upstream fix applied in net-p2p/linuxdcpp-1.0.1-r1.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-06-29 22:15:47 UTC
Sorry for not noting earlier, there is another remote DoS:
http://cvs.berlios.de/cgi-bin/viewcvs.cgi/linuxdcpp/linuxdcpp/client/NmdcHub.cpp.diff?r1=1.14&r2=1.15&sortby=date
Comment 4 Santiago M. Mola (RETIRED) gentoo-dev 2008-06-29 22:51:56 UTC
Arf, sorry, I actually noted it and for some reason missed its inclusion. Now included in 1.0.1-r2. I hope there's no third because I'll go to bed soon ;-)
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2008-06-29 23:18:12 UTC
Arches, please test and mark stable:
=net-p2p/linuxdcpp-1.0.1-r2
Target keywords : "amd64 x86"
Comment 6 Christian Faulhammer (RETIRED) gentoo-dev 2008-06-30 07:52:11 UTC
x86 stable
Comment 7 Santiago M. Mola (RETIRED) gentoo-dev 2008-07-03 12:01:44 UTC
amd64 stable, vulnerable version removed from the tree.
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-07-06 18:21:40 UTC
glsa vote... client DoS, I vote NO.
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2008-07-06 21:48:57 UTC
NO, closing.