|
Bugzilla – Full Text Bug Listing |
| Summary: | several security problems in Ethereal 0.9.12 | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Petr Ostadal <postadal> |
| Component: | Incidents | Assignee: | Thomas Biege <thomas> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | lmuelle, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2003-0432: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) CVSSv2:NVD:CVE-2003-0428:5.0:(AV:N/AC:L/Au:N/C:N/I:N/A:P) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: |
patchinfo
putonftp |
||
|
Description
Petr Ostadal
2003-06-12 21:49:14 UTC
It looks like we need to create an update for this. Petr, can you do this, please? yes I work on it, but backport for all old version take me some time ;(... Sure, no problem. Just wanted to make sure we are on the same page :) Related info (for tracking purposes and advisory) http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0428 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0429 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0431 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0432 http://www.ethereal.com/appnotes/enpa-sa-00010.html And if possible please add the CAN ids to the changelog. Fixed, now I waiting for p&p from Thomas Created attachment 13088 [details]
patchinfo
Created attachment 13089 [details]
putonftp
Is this package tested enough too bypass QA testing? I tested it but I think it needs to test more protocols than I did it. Fixed packages and patchinfo were submited. I think I will approve it w/o further testing. Ok So, I was thinking wrong. I needs testing. QA is informed. Is the package from SuSE Linux 8.0 not affected? I didn't find a fixed version in the SuSE Linux 8.0 update tree of euklid. The fix is on the way... approved approved CVE-2003-0432: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) |