Bug#395248: ngrep: insecure signal handler may cause crashes

2006-10-26 Thread Romain Francoise
severity 395248 serious tags 395248 upstream kthxbye Sam Hocevar (Debian packages) [EMAIL PROTECTED] writes: ngrep's signal handler, clean_exit(), calls free() and other cleanup functions in a non-idempotent way. Good catch, thanks for the report. This is probably a security issue, too,

Bug#395248: ngrep: insecure signal handler may cause crashes

2006-10-26 Thread Romain Francoise
It turns out that this bug was fixed in CVS already, a new ngrep release is pending. Thanks, -- ,''`. : :' :Romain Francoise [EMAIL PROTECTED] `. `' http://people.debian.org/~rfrancoise/ `- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe.

Bug#395248: ngrep: insecure signal handler may cause crashes

2006-10-25 Thread Sam Hocevar (Debian packages)
Package: ngrep Version: 1.44-2 Severity: important Tags: security ngrep's signal handler, clean_exit(), calls free() and other cleanup functions in a non-idempotent way. There is an easy way to trigger the bug by running ngrep . | cat, then pressing Ctrl-C. ngrep will get a SIGINT signal from