[Bug 1290100] Re: [Need update to 1.10.6] 4 Vulnerabilities buffer overflow crash ddos

2014-03-13 Thread Alberto Jovito
Synchronize the wireshark package from debian wheezy to my ppa for precise with syncpackage https://launchpad.net/~thedemon007/+archive/thedemon007 tried it and it works well. This is the debdiff he gave me. You can see in the changelog that a lot of vulnerabilities are corrected.

[Bug 1290100] Re: [Need update to 1.10.6] 4 Vulnerabilities buffer overflow crash ddos

2014-03-12 Thread Alberto Jovito
@Sebastien They should not of unsubscribed, not yet fixed in previous versions of ubuntu. @Scott To saucy can make a fake sync debian Jessie? https://wiki.ubuntu.com/SecurityTeam/SponsorsQueue Regarding precise would have to also update the libraries. I think it is also feasible to make a fake

[Bug 1290100] Re: [Need update to 1.10.6] 4 Vulnerabilities buffer overflow crash ddos

2014-03-12 Thread Martin Pitt
Unsubscribing sponsors; trusty is done, there's nothing else to sponsor. ubuntu-sponsors cannot do security updates for stables. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1290100 Title: [Need

[Bug 1290100] Re: [Need update to 1.10.6] 4 Vulnerabilities buffer overflow crash ddos

2014-03-12 Thread Martin Pitt
Nevermind, this is already only subscribed by security-sponsors. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1290100 Title: [Need update to 1.10.6] 4 Vulnerabilities buffer overflow crash ddos

[Bug 1290100] Re: [Need update to 1.10.6] 4 Vulnerabilities buffer overflow crash ddos

2014-03-11 Thread Sebastien Bacher
(ubuntu-security-sponsors should probably be unsubscribed since there is no nothing to sponsor at the moment there) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1290100 Title: [Need update to

[Bug 1290100] Re: [Need update to 1.10.6] 4 Vulnerabilities buffer overflow crash ddos

2014-03-10 Thread Alberto Jovito
I see that vulnerabilities are already corrected in all or almost all versions of debian but not yet synchronized packages. It should change the links repository, see bug #1282805 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1290100] Re: [Need update to 1.10.6] 4 Vulnerabilities buffer overflow crash ddos

2014-03-10 Thread Scott Kitterman
This bug was fixed in the package wireshark - 1.10.6-1 Sponsored for Alberto Jovito (thedemon007) --- wireshark (1.10.6-1) unstable; urgency=high * New upstream release 1.10.6 - release notes: https://wireshark.org/docs/relnotes/wireshark-1.10.6.html - security fixes:

[Bug 1290100] Re: [Need update to 1.10.6] 4 Vulnerabilities buffer overflow crash ddos

2014-03-10 Thread Scott Kitterman
Debian has the new release, so for trusty, we can sync that. It would be really useful if you could prepare debdiffs for precise and saucy. ** Also affects: wireshark (Ubuntu Saucy) Importance: Undecided Status: New ** Also affects: wireshark (Ubuntu Trusty) Importance: Undecided

[Bug 1290100] Re: [Need update to 1.10.6] 4 Vulnerabilities buffer overflow crash ddos

2014-03-09 Thread Ubuntu Foundations Team Bug Bot
The attachment wireshark_1.10.6-1_security_fix_trusty-proposed seems to be a debdiff. The ubuntu-sponsors team has been subscribed to the bug report so that they can review and hopefully sponsor the debdiff. If the attachment isn't a patch, please remove the patch flag from the attachment, remove