[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2011-08-11 Thread Bug Watch Updater
** Changed in: debian Status: Unknown => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/290716 Title: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vu

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2009-02-12 Thread Andreas Wenning
Marking as fix released, as the packages are already copied to -updates and -security. ** Changed in: wireshark (Ubuntu Gutsy) Status: Fix Committed => Fix Released ** Changed in: wireshark (Ubuntu Hardy) Status: Fix Committed => Fix Released ** Changed in: wireshark (Ubuntu Intrep

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2009-02-02 Thread Rolf Leggewie
I'd be happy to test the proposed packages, except I would not know how. There is no test-case. I could install the packages and report whether that goes smoothly or not. But I don't think that kind of feedback to be sufficient. -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2009-01-15 Thread Jamie Strandboge
Can people from motu-swat test these proposed wireshark packages? Thanks in advance! -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification because you are a member of Ubuntu Bugs, whic

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2009-01-15 Thread Jamie Strandboge
** Tags added: verification-needed -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailin

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2009-01-15 Thread Jamie Strandboge
These are all in proposed, please test and give feedback here. Please see https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Thank you in advance! -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bu

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2009-01-09 Thread Kees Cook
** Changed in: wireshark (Ubuntu Gutsy) Importance: Undecided => Medium ** Changed in: wireshark (Ubuntu Hardy) Importance: Undecided => Medium ** Changed in: wireshark (Ubuntu Intrepid) Importance: Undecided => Medium -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2009-01-07 Thread Kees Cook
I've uploaded these for building in the security queue. Once they are ready, we can put them through -proposed and finally into -security. Thanks again! https://launchpad.net/~ubuntu-security-proposed/+archive ** Changed in: wireshark (Ubuntu Intrepid) Status: In Progress => Fix Committed

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2009-01-07 Thread Kees Cook
Thanks for these debdiffs! Have the resulting builds been tests on each release as well? -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2009-01-07 Thread Kees Cook
Fixed in Jaunty via Debian merge. ** Changed in: wireshark (Ubuntu) Status: New => Fix Released ** Changed in: wireshark (Ubuntu) Importance: Undecided => Medium -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bug

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-12-09 Thread Stefan Lesicnik
Hi. These patches should be complete. I think Debian has merged them already. I will see if I can get an admin to upload these. -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-12-09 Thread xarax
Could someone please comment on the progress of resolving this bug. I use wireshark in Intrepid and I'm a bit worried about these vulnerabilities. Thanks. -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You receiv

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-11-02 Thread Stefan Lesicnik
Gutsy includes 0.99.6 of Wireshark and CVE-2008-4685 should not apply according the CVE description, although using the attached CVE POC exploit, it was possible to segfault Wireshark. After applying the fix for CVE 2008-4685 the segfault no longer occured. ** Attachment added: "gutsy-debdiff"

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-11-02 Thread Stefan Lesicnik
** Attachment added: "hardy-debdiff" http://launchpadlibrarian.net/19239904/hardy-debdiff -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification because you are a member of Ubuntu B

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Kees Cook
** Changed in: wireshark (Ubuntu Intrepid) Status: New => In Progress -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification because you are a member of Ubuntu Bugs, which is sub

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
** Changed in: wireshark (Ubuntu Intrepid) Assignee: (unassigned) => Stefan Lesicnik (stefanlsd) ** Changed in: wireshark (Ubuntu Hardy) Assignee: (unassigned) => Stefan Lesicnik (stefanlsd) ** Changed in: wireshark (Ubuntu Gutsy) Assignee: (unassigned) => Stefan Lesicnik (stefanls

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
** Bug watch added: Debian Bug tracker #503589 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503589 ** Also affects: debian via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503589 Importance: Unknown Status: Unknown -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
Intrepid debdiff attached. I am in contact with the Debian maintainer and will forward all relevant patches. ** Attachment added: "intrepid-debdiff" http://launchpadlibrarian.net/19069793/intrepid-debdiff -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabil

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
As per the CVE's. All releases up to 1.0.3 are affected by these bugs. These POC are taken from the original wireshark bug tracker and just renamed to easier identify which belongs to which CVE. All of these bugs were always reproducible, except for CVE_2008-4685 which happened intermittently. I

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
** Attachment added: "CVE_2008-4685-fred2.pcap" http://launchpadlibrarian.net/19069687/CVE_2008-4685-fred2.pcap -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification because you ar

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
** Attachment added: "CVE_2008-4685-fred1.pcap" http://launchpadlibrarian.net/19069679/CVE_2008-4685-fred1.pcap -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification because you ar

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
** Attachment added: "CVE_2008-4685-fred.pcap" http://launchpadlibrarian.net/19069672/CVE_2008-4685-fred.pcap -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification because you are

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
** Attachment added: "CVE_2008-4684-sample_bug.pcap" http://launchpadlibrarian.net/19069667/CVE_2008-4684-sample_bug.pcap -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification beca

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
** Attachment added: "CVE_2008-4683-fuzz-2008-04-29-6028.pcap" http://launchpadlibrarian.net/19069657/CVE_2008-4683-fuzz-2008-04-29-6028.pcap -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
** Attachment added: "CVE_2008-4682-wireshark.ncf" http://launchpadlibrarian.net/19069648/CVE_2008-4682-wireshark.ncf -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this bug notification because

[Bug 290716] Re: [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities

2008-10-30 Thread Stefan Lesicnik
** Attachment added: "CVE_2008-4680-poc_usb_urb_segfault.pcap" http://launchpadlibrarian.net/19069647/CVE_2008-4680-poc_usb_urb_segfault.pcap -- [CVE 2008-468[1-5] - Wireshark up to 1.0.3 affected by multiple security vulnerabilities https://bugs.launchpad.net/bugs/290716 You received this