Bug#357580: firebird2-*-server: remotelly crashable

2006-03-21 Thread Damyan Ivanov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Martin Schulze wrote: This is CVE-2004-2043, please mention it in the changelog when you're Great! Thanks. doing the next upload. Sure. - -- dam -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.2.2 (GNU/Linux) Comment: Using GnuPG with Mozilla

Bug#357580: firebird2-*-server: remotelly crashable

2006-03-21 Thread Martin Schulze
Damyan Ivanov wrote: Here's a patch that fixes the crash. The fix is rather ugly IMHO, but this is what upstream proposed. The patch looks good. I've requested a CVE name as well, will upload fixed packages for sarge tonight. Regards, Joey -- Of course, I didn't mean that, which is

Bug#357580: firebird2-*-server: remotelly crashable

2006-03-21 Thread Martin Schulze
Damyan Ivanov wrote: Here's a patch that fixes the crash. The fix is rather ugly IMHO, but this is what upstream proposed. Please apply it to stable version of firebird2. Unstable package is due for upload. More information (discovery, reproduction) on http://bugs.debian.org/358580

Bug#357580: firebird2-*-server: remotelly crashable

2006-03-20 Thread Damyan Ivanov
reassign 357580 firebird2-super-server,libfbembed1 thanks Hi, Here's a patch that fixes the crash. The fix is rather ugly IMHO, but this is what upstream proposed. Please apply it to stable version of firebird2. Unstable package is due for upload. More information (discovery, reproduction) on

Bug#357580: firebird2-*-server: remotelly crashable

2006-03-18 Thread Damyan Ivanov
Package: firebird2-super-server,firebird2-classic-server Version: 1.5.3.4870-2 Severity: critical Tags: security help Justification: root security hole As noted in [1], fbserver (the daemon listening for TCP, found in firebird2-super-server, source package firebird2) crashes if given too long