|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2005-2040 : Heimdal telnetd buffer overflow in getterminaltype | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Dennis Conrad <dcon> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P5 - None | CC: | heiko.rommel, lnussel, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | SLES 9 | ||
| Whiteboard: | qa | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: |
overflow.patch
log |
||
|
Description
Dennis Conrad
2005-06-21 13:29:58 UTC
well spotted, was still unknown to us. Thanks! Created attachment 39580 [details]
overflow.patch
0.6.4 -> 0.6.5 patch extract. untested
Packages are submitted to sles8,sles9,slec and 8.2 - 9.2 Can you please submit patchinfos? swampid: 1625 patchinfos submitted, only containing "heimdal" itself, since this is the package with "telnetd" inside. Hi, qa can not approve the maintenance update of heimdal because we currently can not reliably test the telnetd and sshd part. Sometime it works, sometime not. Please assist in debugging this. The testcase we ran are http://pdb.suse.de/pdb-testcases.pl?Package=heimdal&Release=27&tcid=5770 The current status can be read in ~rommel/QA/patch-10262/log The failures seem to be independent of architecture and code base. Even re-running the testcases on the same host (including re-creation of the complete Kerberos setup) does provide random outcome. I'm totally lost. -- Heiko Rommel rommel@suse.de SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg T: +49 (0) 911 74053 0 F: +49 (0) 911 741 77 55 Created attachment 41141 [details]
log
failed QA log from Heiko.
Vladimir is on vacation this week. helped with QA. approved updates, published advisory. CAN-2005-2040 *** Bug 97195 has been marked as a duplicate of this bug. *** |