Bug#908779: bro: CVE-2018-17019: Fix IRC names command parsing

2019-03-21 Thread Hilko Bengen
* Moritz Mühlenhoff: >> Working on 2.6.1, but I need to get broker (and a new upstream versio >> nof actor-framework) into unstable first. Working on that, too. It's a pity that this did not work out... > With buster being in full freeze, can you backport CVE-2018-17019 and > CVE-2018-16807 to 2

Bug#908779: bro: CVE-2018-17019: Fix IRC names command parsing

2019-03-14 Thread Moritz Mühlenhoff
On Tue, Jan 29, 2019 at 02:19:20AM +0100, Hilko Bengen wrote: > * Moritz Mühlenhoff: > > >> CVE-2018-17019[0]: > >> | In Bro through 2.5.5, there is a DoS in IRC protocol names command > >> | parsing in analyzer/protocol/irc/IRC.cc. > > > > ping, can we get this one (and CVE-2018-16807) uploaded s

Bug#908779: bro: CVE-2018-17019: Fix IRC names command parsing

2019-02-12 Thread Hilko Bengen
* Hilko Bengen: >>> | In Bro through 2.5.5, there is a DoS in IRC protocol names command >>> | parsing in analyzer/protocol/irc/IRC.cc. >> >> ping, can we get this one (and CVE-2018-16807) uploaded still in time >> for buster? > > Working on 2.6.1, but I need to get broker (and a new upstream vers

Bug#908779: bro: CVE-2018-17019: Fix IRC names command parsing

2019-01-28 Thread Hilko Bengen
* Moritz Mühlenhoff: >> CVE-2018-17019[0]: >> | In Bro through 2.5.5, there is a DoS in IRC protocol names command >> | parsing in analyzer/protocol/irc/IRC.cc. > > ping, can we get this one (and CVE-2018-16807) uploaded still in time > for buster? Working on 2.6.1, but I need to get broker (and

Bug#908779: bro: CVE-2018-17019: Fix IRC names command parsing

2019-01-28 Thread Moritz Mühlenhoff
On Thu, Sep 13, 2018 at 10:39:17PM +0200, Salvatore Bonaccorso wrote: > Source: bro > Version: 2.5-1 > Severity: important > Tags: patch security upstream > Control: found -1 2.5.5-1 > > Hi, > > The following vulnerability was published for bro. > > CVE-2018-17019[0]: > | In Bro through 2.5.5, t

Bug#908779: bro: CVE-2018-17019: Fix IRC names command parsing

2018-09-13 Thread Salvatore Bonaccorso
Source: bro Version: 2.5-1 Severity: important Tags: patch security upstream Control: found -1 2.5.5-1 Hi, The following vulnerability was published for bro. CVE-2018-17019[0]: | In Bro through 2.5.5, there is a DoS in IRC protocol names command | parsing in analyzer/protocol/irc/IRC.cc. If you