Your message dated Sun, 01 Sep 2019 12:06:54 +0000
with message-id <[email protected]>
and subject line Bug#881862: fixed in tcpdump 4.9.3~git20190901-1
has caused the Debian Bug report #881862,
regarding tcpdump: CVE-2017-16808: heap-based buffer over-read related to 
aoe_print in print-aoe.c and lookup_emem in addrtoname.c
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
881862: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881862
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: tcpdump
Version: 4.9.2-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/the-tcpdump-group/tcpdump/issues/645
Control: found -1 4.9.2-1~deb9u1
Control: found -1 4.9.2-1~deb8u1

Hi,

the following vulnerability was published for tcpdump. This is
basically just to track the issue in Debian BTS. Upstream said that
[1] is not the first report and the issue is been reported alrady, and
will be fixed in a future release. No further information in [1] apart
that from upstream project.

CVE-2017-16808[0]:
| tcpdump 4.9.2 has a heap-based buffer over-read related to aoe_print in
| print-aoe.c and lookup_emem in addrtoname.c.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-16808
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16808
[1] https://github.com/the-tcpdump-group/tcpdump/issues/645

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: tcpdump
Source-Version: 4.9.3~git20190901-1

We believe that the bug you reported is fixed in the latest version of
tcpdump, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Romain Francoise <[email protected]> (supplier of updated tcpdump package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 01 Sep 2019 13:05:24 +0200
Source: tcpdump
Architecture: source
Version: 4.9.3~git20190901-1
Distribution: unstable
Urgency: low
Maintainer: Romain Francoise <[email protected]>
Changed-By: Romain Francoise <[email protected]>
Closes: 881862 935112
Changes:
 tcpdump (4.9.3~git20190901-1) unstable; urgency=low
 .
   * New upstream snapshot from the tcpdump-4.9 branch:
     + Includes fix for CVE-2017-16808 (closes: #881862).
     + Fixes ESP decryption on ppc64el (and others), re-enable tests.
   * Drop root privileges by default (closes: #935112):
     + debian/rules: Configure --with-user=tcpdump.
     + debian/tcpdump.post{inst,rm}: Create/delete a 'tcpdump' system group
       and user.
     + debian/control: Add dependency on adduser.
     + debian/patches/drop-privs-after-opening-savefile.diff: New patch
       (from Fedora) to drop root privileges *after* opening the savefile
       when possible, to alleviate possible inconvenience if the target
       directory is not writable by user tcpdump.
     + debian/patches/drop-privs-silently.diff: New patch (from Fedora) to
       drop root privileges silently.
     + debian/usr.sbin.tcpdump: Add chown capability, and update rules
       about device discovery.
     + debian/NEWS: Mention how to run tcpdump as root.
   * Bump Standards-Version to 4.4.0.
Checksums-Sha1:
 07173e92b42c219ee5221e0cce1d26f858704d66 1971 tcpdump_4.9.3~git20190901-1.dsc
 7192d72a18e961b8cc99d487920f74bb5254ceba 2299118 
tcpdump_4.9.3~git20190901.orig.tar.gz
 f5527cb3fcca2fd57bc18aa5cfb47c6b9de51bcf 17076 
tcpdump_4.9.3~git20190901-1.debian.tar.xz
 74408cf228c6a3a9f5f81168b82bab3999c68d04 5585 
tcpdump_4.9.3~git20190901-1_source.buildinfo
Checksums-Sha256:
 bbb10de1ba023799c7ed595e8f28b15b14c5d6e440eb036ef5c58c19895bdb06 1971 
tcpdump_4.9.3~git20190901-1.dsc
 6ca424621e53d9d9d0a7bd5ec461895ce4e678266c2214536c30ef9b4e2a20fe 2299118 
tcpdump_4.9.3~git20190901.orig.tar.gz
 dae49a90cf92d88677c4f110fe6dd0f0066508cab3c398e15533bcc46da60c59 17076 
tcpdump_4.9.3~git20190901-1.debian.tar.xz
 bc33d151aa465a73af63afd1557c06a264bd5a6528aac02d7e8519c0b8badb2b 5585 
tcpdump_4.9.3~git20190901-1_source.buildinfo
Files:
 48b5f647ae9a9170ab0a648d0fea849c 1971 net optional 
tcpdump_4.9.3~git20190901-1.dsc
 7d3931209559a54bf78b2a45ee3a5943 2299118 net optional 
tcpdump_4.9.3~git20190901.orig.tar.gz
 a49eacf192bea0157ef3833bdaaad803 17076 net optional 
tcpdump_4.9.3~git20190901-1.debian.tar.xz
 ed979b1e114ebb2b454e9924fad34370 5585 net optional 
tcpdump_4.9.3~git20190901-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEvjSXQsqYfs1+d+QtrRX0NfBfli0FAl1rqnAACgkQrRX0NfBf
li3mNQ/9Ejp+IDngiqOoskCJny0/V8Lj9dRvEXqxULub4jEvO0WOXjOvuMwbSn/6
ilFsv6sKuk8nLcbuYiaHiyTVcbIKgZEwFc9Ky2bIbYiWIobFx8vPdoH0RmrdYOXC
IphsW9g9hEeqg+KSJPs4dqK1AvWKxT5+PCV8TNZgwD+NP5GilAV8PSKLEyHCZGTa
zg+uDfF2I1AqqQZBZnf4aK/bZOnbSZ2Bz6O098BweeTfxp2RVhxEWP14ONU+XlNA
MNp7bu3M7m7LpVEn5SI+7uof1aL4m4yq55XwVZNWfnLf0hYrdP6o6egVFyTtFhEj
qAQHN7C9X9/aWhrFzhXpUf9VKIDciAQ8LbkxShe8hfX3i6XHCfr4RTa6znWoN53w
bNj9pSO9fgaT/qAaudgRLewofV5Yj0Q8LMiKHHComS6NrdfgOabVZzoPGZOq5+EZ
u7Yk3UHLavFznmoOOQVYJpr21yrH6nFj3pQbCCF5jsxxlZHY23vl5VsdFVIoHKbB
ah8mBwSkTeOt9GCIzQuJKdcCdQoL8yTvip0yWls64n0MqRCTM5udLxlmD1RcRBQD
v5dp6fiLEXJ59U9BW0vumlUB5hQH2OWpOx3zOrRseyQiwJGF+ljRVLIQz7UaYOcx
RGKyaiG8hpy16MWcCRQ6/qBvqCyvOIga9KkeMLyxMyYS8fKJGHA=
=o7dB
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to