Bug#226356: Buffer overflow vulnerability (CAN-2003-0850)

2004-01-07 Thread Colin Watson
On Tue, Jan 06, 2004 at 11:22:55AM +, Steve Kemp wrote: > On Mon, Jan 05, 2004 at 06:17:07PM -0800, Matt Zimmerman wrote: > > Package: libnids > > Severity: grave > > > > "The TCP reassembly functionality in libnids before 1.18 allows remote > > attackers to cause "memory corruption" and possi

Bug#226356: Buffer overflow vulnerability (CAN-2003-0850)

2004-01-07 Thread Colin Watson
On Mon, Jan 05, 2004 at 06:17:07PM -0800, Matt Zimmerman wrote: > Package: libnids > Severity: grave > > "The TCP reassembly functionality in libnids before 1.18 allows remote > attackers to cause "memory corruption" and possibly execute arbitrary code > via "overlarge TCP packets." > > http://cv

Bug#226356: Buffer overflow vulnerability (CAN-2003-0850)

2004-01-06 Thread Steve Kemp
On Mon, Jan 05, 2004 at 06:17:07PM -0800, Matt Zimmerman wrote: > Package: libnids > Severity: grave > > "The TCP reassembly functionality in libnids before 1.18 allows remote > attackers to cause "memory corruption" and possibly execute arbitrary code > via "overlarge TCP packets." > > http://cv

Bug#226356: Buffer overflow vulnerability (CAN-2003-0850)

2004-01-06 Thread Matt Zimmerman
Package: libnids Severity: grave "The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets." http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0850 An update to version 1.18 sh