Re: debian dhcpd, old format string bug

From: Tarragon Allen (tarragon_at_onthe.net.au)
Date: 10/28/04

  • Next message: Chris Frey: "Re: zgv image viewing heap overflows"
    To: bugtraq@securityfocus.com
    Date: Thu, 28 Oct 2004 10:31:38 +1000
    
    

    On Tuesday 26 October 2004 10:37, infamous41md@hotpop.com wrote:
    > Subject:
    >
    > Debian dhcpd package.
    >
    > http://packages.debian.org/stable/net/dhcp
    >
    > It is vulnerable to the '02 format string bug.
    >
    > http://www.cert.org/advisories/CA-2002-12.html

    Firstly, good etiquette would have been for you to actually report the bug
    with Debian. I don't see any bugs raised against any of the appropriate
    packages regarding this.

    Secondly, the advisory you refer to is only mentioning DHCP 3.0+. The Debian
    package you referred to is 2.0pl5. Perhaps you are referring to:

    http://packages.debian.org/stable/net/dhcp3-server

    Which is presently at 3.0.1rc9. The CERT advisory refers to 3.01 to 3.01r8
    inclusive.

    Are you saying the CERT advisory applies to other versions of DHCP?

    t

    -- 
    http://moto-coda.org/public.gpg.key
    

  • Next message: Chris Frey: "Re: zgv image viewing heap overflows"

    Relevant Pages

    • Re: debian dhcpd, old format string bug
      ... >> Debian dhcpd package. ... good etiquette would have been for you to actually report the bug ... the etiquette I need, but thanks for the moral support. ... > package you referred to is 2.0pl5. ...
      (Bugtraq)
    • Re: Lost Labyrinth
      ... > I need someone that helps me doing a Debian package and do not want to report ... standard way is to report a bug against this wnpp package, ... according to Debians definition of free software. ...
      (Debian-User)
    • Re: [Ada in Debian] GtkAda and GNAT versions
      ... This is a bug in the package gnat-3.4; ... this is intended (that gtkada can only be used with 3.15p at debian). ...
      (comp.lang.ada)
    • Re: debian dhcpd, old format string bug
      ... >> Debian dhcpd package. ... good etiquette would have been for you to actually report the bug ... > package you referred to is 2.0pl5. ... This is a different vulnerability than the one referenced to with CA-2002-12. ...
      (Bugtraq)
    • Re: i think I switched to Etch without knowing it
      ... >> Apt uses its default behavior if you don't have an apt.conf file. ... > It seems like you are referring to package version. ... I would say my Debian version is sarge because all the packages on my ...
      (Debian-User)