Your message dated Sat, 09 May 2015 17:47:21 +0000
with message-id <[email protected]>
and subject line Bug#784571: fixed in dnsmasq 2.62-3+deb7u3
has caused the Debian Bug report #784571,
regarding dnsmasq: Wheezy regression caused by CVE-2015-3294/2.62-3+deb7u2 w/
bind-interfaces
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
784571: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784571
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: dnsmasq
Version: 2.62-3
Severity: important
Tags: security upstream patch fixed-upstream
Hi,
the following vulnerability was published for dnsmasq.
CVE-2015-3294[0]:
denial of service
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2015-3294
[1] http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2015q2/009382.html
[2
http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=ad4a8ff7d9097008d7623df8543df435bfddeac8
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: dnsmasq
Source-Version: 2.62-3+deb7u3
We believe that the bug you reported is fixed in the latest version of
dnsmasq, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated dnsmasq package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 06 May 2015 21:37:29 +0200
Source: dnsmasq
Binary: dnsmasq dnsmasq-base dnsmasq-utils
Architecture: source amd64 all
Version: 2.62-3+deb7u3
Distribution: wheezy-security
Urgency: high
Maintainer: Simon Kelley <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Description:
dnsmasq - Small caching DNS proxy and DHCP/TFTP server
dnsmasq-base - Small caching DNS proxy and DHCP/TFTP server
dnsmasq-utils - Utilities for manipulating DHCP leases
Closes: 784571
Changes:
dnsmasq (2.62-3+deb7u3) wheezy-security; urgency=high
.
* Non-maintainer upload by the Security Team.
* Handle case where SO_REUSEPORT may be defined but not supported by
the running kernel.
The update for CVE-2015-3294 caused a regression for the armel and armhf
builds due to a newer linux-libc-dev package installed in the wheezy
chroots used for the build. The libc headers defined SO_REUSEPORT,
whereas the kernel in wheezy does not support it uncovering this
problem. (Closes: #784571)
* Set SO_REUSEADDR as well as SO_REUSEPORT on DHCP sockets when
both are available
Checksums-Sha1:
1bd2ae805f180475dc014babbe86ccc7591151c6 1801 dnsmasq_2.62-3+deb7u3.dsc
0e579055b5e1f593a3bbe1d2dc368b68aa6a586e 21635 dnsmasq_2.62-3+deb7u3.diff.gz
7ee1f126e62f7cbea34d7d61f160d829f70dbbb6 370616
dnsmasq-base_2.62-3+deb7u3_amd64.deb
2c6601342e9313c807580cb3f10faa8c2877c18a 19002
dnsmasq-utils_2.62-3+deb7u3_amd64.deb
a676bfb63a283cf7e84a094d31e46f5f5d07e950 16316 dnsmasq_2.62-3+deb7u3_all.deb
Checksums-Sha256:
5daa6c534676b3459937f6b946ed1b1f285be175237dde55b79c84b21c51f007 1801
dnsmasq_2.62-3+deb7u3.dsc
408df7ce66c5090c89cfcc86725cca4701c478f96aae7336ab8d3dbea5c3e2fd 21635
dnsmasq_2.62-3+deb7u3.diff.gz
5494fe9c7bb7be1df6ae87dc722ee8dd666e47af889242585d8c47ea011a83d0 370616
dnsmasq-base_2.62-3+deb7u3_amd64.deb
73ea22d327663c120b0ec128c4f29ca8a0e78dace42937c13568311a3f0d33bd 19002
dnsmasq-utils_2.62-3+deb7u3_amd64.deb
ac19ae063635acbb011f54f3eb634d6cafc268e0145d776cdf71352e9c378180 16316
dnsmasq_2.62-3+deb7u3_all.deb
Files:
fd699b4c8bd0f62512ad9783a3ebc28f 1801 net optional dnsmasq_2.62-3+deb7u3.dsc
ed83b2bd25d0f6e8c381da5cbeb2e83e 21635 net optional
dnsmasq_2.62-3+deb7u3.diff.gz
293e3e2a25ff1989c007792052091d43 370616 net optional
dnsmasq-base_2.62-3+deb7u3_amd64.deb
4612f4b60adea465ace9c0dbcf60539b 19002 net optional
dnsmasq-utils_2.62-3+deb7u3_amd64.deb
7a754ba435d40a6bec8ebdb622e30e45 16316 net optional
dnsmasq_2.62-3+deb7u3_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJVSm24AAoJEAVMuPMTQ89EiX0P/0/D3mm/aw2FM3o/KSOCrhu/
mz026b1Gy1JhVWISxRyx1sBAOcTR0ednXuC6TBmkDiOpQOEWMFV6ynYe2RHoPmVm
HYrkfw8b5HESb7GLdgg3SZF6BGCyTUOoztiAA8Ne4/cLtJaNSyR7d/U5lILyFg2v
EOTYRmK0FcR8PGo3ialrgOIfE17rRWNXy7HQBqBiFJ4dxBtSmy34tBnX62j+VybZ
db403aQhjEN8Wa3zawo2EDpySugxrg2nPjpIRnXH1VqHbh+j3n5+DL8M/I86yrb0
XDrPogQ5HYUlZX7L1oXPKedehp+RFPlqwK8khFN3eSctUbcskyS8EgINaf6FiuOk
WU30XmWJICuxETIBP4DjHz4xt0umUgmLMQ+r4MEJfrAQuB1e0Lu/Wn6kaUjnrnHK
oR5upGdneKKFaHcP7OYaEu0A1Qbt/WIF6TmLlQ42sC5sK0DE6JOd+5hXAWHmcVpk
ufTXt6PMDz9bKLSruQ3N0jST7lJuUkJ2LXasXxK9cjpkEbKRGCA7l+hRc+n6iTfs
eOJ9uIYPxT2vGQR7/CIDPUC7zX8MGeyasKaaWXloETyAJKEfcIxlgKUJOmPwINZ9
IJOGOf41u5hk7FgkRB0v/khFyEqlXE7cktmzsmPe8MzTWfGkN/TavcHbpj3wSHuD
wKzxElP1ZLnS3nNNqz/l
=QeFq
-----END PGP SIGNATURE-----
--- End Message ---