Bug#564110: r8169: Fix for CVE-2009-1389 introduces denial of service issue

2010-08-01 Thread Ben Hutchings
On Sun, 2010-08-01 at 17:53 -0400, Michael Gilbert wrote: > can we downgrade the severity of this issue since there is a fix > included (even though it isn't ideal)? it's currently RC. Let's clone it, close this one and downgrade the clone. That way we will have proper version-tracking of the or

Bug#564110: r8169: Fix for CVE-2009-1389 introduces denial of service issue

2010-08-01 Thread Michael Gilbert
can we downgrade the severity of this issue since there is a fix included (even though it isn't ideal)? it's currently RC. best wishes, mike -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#564110: r8169: Fix for CVE-2009-1389 introduces denial of service issue

2010-03-17 Thread Ben Hutchings
On Wed, Mar 17, 2010 at 06:01:43PM +0100, maximilian attems wrote: > issue got fixed in 2.6.32.9. > is stable affected? It's not properly fixed - if you ever change MTU the vulnerability will be reopened. And the fix introduces a severe performance regression even for hardware that doesn't have

Bug#564110: r8169: Fix for CVE-2009-1389 introduces denial of service issue

2010-03-17 Thread maximilian attems
issue got fixed in 2.6.32.9. is stable affected? Ben wanted to review it before stable upload as rh/fedora fix went throug several iterations. although they seem to have settled now. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble

Bug#564110: r8169: Fix for CVE-2009-1389 introduces denial of service issue

2010-01-07 Thread Ben Hutchings
Julien Cristau pointed out the thread where it appears that Red Hat has allocated CVE-2009-4537 for this. Ben. -- Ben Hutchings To err is human; to really foul things up requires a computer. signature.asc Description: This is a dig

Bug#564110: r8169: Fix for CVE-2009-1389 introduces denial of service issue

2010-01-07 Thread Ben Hutchings
Package: linux-2.6 Version: 2.6.32-4 Severity: serious Tags: security Fabian Yamaguchi made a presentation at 26C3 which included a bug in r8169 reintroduced by: commit fdd7b4c3302c93f6833e338903ea77245eb510b4 Author: Eric Dumazet