Bugzilla – Bug 106134
VUL-0: CVE-2005-2627: kismet: heap overflow leads to possible code execution
Last modified: 2021-12-07 16:03:26 UTC
Hi, looks like we need a full update. http://www.gentoo.org/security/en/glsa/glsa-200508-10.xml
CAN-2005-2626: attack via unprintable chars in SSID CAN-2005-2627: integer overflows lead to heap overflow
SM-Tracker-2103
The author says he still doesn't know all the details, should we wait or go with the update? In this situation it would meant update for all dists I'm afraid.
Thomas, what do you suggest?
The package is not worth the work of extracting a patch I think, so let's just do a version upgrade.
aj?
Go ahead.
fixes submited
SM-Tracker-2160
/work/src/done/PATCHINFO/kismet.patch.box
packages released
closing...
CVE-2005-2627: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)