Bug#446354: dhcp: stack-based buffer overflow (CVE-2007-5365)

2007-10-27 Thread Nico Golde
Hi, Uploading a 0-day NMU based on Steffens patch since Steffen is away at this weekend and noone else seems to do it :) Kind regards Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. diff -u

Bug#446354: dhcp: stack-based buffer overflow (CVE-2007-5365)

2007-10-26 Thread Nico Golde
Hi Steve, any news about the upload? Ping me if you don't have the time and need an NMU. Kind regards Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgp1bgNXYDOgW.pgp Description: PGP

Bug#446354: dhcp: stack-based buffer overflow (CVE-2007-5365)

2007-10-15 Thread Steve Kemp
On Fri Oct 12, 2007 at 22:51:24 +1000, Steffen Joeris wrote: A patch is attached below. Please tell me, if you want to take care of it or if i should upload. Thanks for the patch, I will upload with it. Steve -- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

Bug#446354: dhcp: stack-based buffer overflow (CVE-2007-5365)

2007-10-12 Thread Steffen Joeris
Package: dhcp Severity: grave Tags: security Justification: user security hole Hi The following CVE[0] has been issued against dhcp. CVE-2007-5365: Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2 allows remote attackers to execute