Bug 106134 (CVE-2005-2627)

Summary: VUL-0: CVE-2005-2627: kismet: heap overflow leads to possible code execution
Product: [Novell Products] SUSE Security Incidents Reporter: Thomas Biege <thomas>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P5 - None CC: patch-request, security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: All   
URL: http://www.gentoo.org/security/en/glsa/glsa-200508-10.xml
Whiteboard: CVE-2005-2627: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Found By: Other Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Thomas Biege 2005-08-22 12:20:36 UTC
Hi,
looks like we need a full update.
http://www.gentoo.org/security/en/glsa/glsa-200508-10.xml
Comment 1 Thomas Biege 2005-08-22 12:24:08 UTC
CAN-2005-2626: attack via unprintable chars in SSID
CAN-2005-2627: integer overflows lead to heap overflow
Comment 2 Thomas Biege 2005-08-22 12:27:33 UTC
SM-Tracker-2103
Comment 3 Marian Jancar 2005-08-22 15:48:28 UTC
The author says he still doesn't know all the details, should we wait or go with
the update? In this situation it would meant update for all dists I'm afraid.
Comment 4 Andreas Jaeger 2005-08-22 15:53:46 UTC
Thomas, what do you suggest?
Comment 5 Thomas Biege 2005-08-23 06:38:49 UTC
The package is not worth the work of extracting a patch I think, so let's just
do a version upgrade.
Comment 6 Marcus Meissner 2005-08-24 17:01:59 UTC
aj? 
Comment 7 Andreas Jaeger 2005-08-25 06:48:17 UTC
Go ahead.
Comment 8 Marian Jancar 2005-08-29 12:22:27 UTC
fixes submited
Comment 9 Thomas Biege 2005-08-29 12:30:42 UTC
SM-Tracker-2160
Comment 10 Thomas Biege 2005-08-29 12:32:54 UTC
/work/src/done/PATCHINFO/kismet.patch.box
Comment 11 Thomas Biege 2005-09-05 08:03:20 UTC
packages released
Comment 12 Thomas Biege 2005-09-05 08:03:35 UTC
closing...
Comment 13 Thomas Biege 2009-10-13 20:47:54 UTC
CVE-2005-2627: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)