Bug#382082: CVE-2006-400[56]: Multiple Remote Vulnerabilities in Bomberclone

2006-08-16 Thread Julien Danjou
On Sat, Aug 12, 2006 at 09:23:04PM +0200, Eduard Bloch wrote:
 tags 382082 + help
 thanks
 
 Could you give me some hints to find an appropriate solution? I am a bit
 exhausted with my spare time in these days.

0.11.7 which fix these bugs has been released.

(If you still need help to package this version, even if I doubt, please,
just ask.)

Cheers,
-- 
Julien Danjou
.''`.  Debian Developer
: :' : http://julien.danjou.info
`. `'  http://people.debian.org/~acid
  `-   9A0D 5FD9 EB42 22F6 8974  C95C A462 B51E C2FE E5CD


signature.asc
Description: Digital signature


Bug#382082: CVE-2006-400[56]: Multiple Remote Vulnerabilities in Bomberclone

2006-08-12 Thread Eduard Bloch
tags 382082 + help
thanks

Could you give me some hints to find an appropriate solution? I am a bit
exhausted with my spare time in these days.

Eduard.

#include hallo.h
* Stefan Fritsch [Tue, Aug 08 2006, 08:56:54PM]:
 package bomberclone
 retitle 382082 CVE-2006-400[56]: Multiple Remote Vulnerabilities in 
 Bomberclone
 thanks
 
 CVE-2006-4005 is about bomberclone, too:
 
 BomberClone 0.11.6 and earlier allows remote attackers to cause a
 denial of service (daemon crash) via (1) a certain malformed
 PKGF_ackreq packet, which triggers a crash in the rscache_add()
 function in pkgcache.c; and (2) an error packet, which is intended to
 be received by clients and force client shutdown, but also triggers
 server shutdown.
 



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#382082: CVE-2006-400[56]: Multiple Remote Vulnerabilities in Bomberclone

2006-08-08 Thread Stefan Fritsch
package bomberclone
retitle 382082 CVE-2006-400[56]: Multiple Remote Vulnerabilities in Bomberclone
thanks

CVE-2006-4005 is about bomberclone, too:

BomberClone 0.11.6 and earlier allows remote attackers to cause a
denial of service (daemon crash) via (1) a certain malformed
PKGF_ackreq packet, which triggers a crash in the rscache_add()
function in pkgcache.c; and (2) an error packet, which is intended to
be received by clients and force client shutdown, but also triggers
server shutdown.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]