Bug#506741: wireshark: DoS caused by sending a SMTP request with large content

2008-12-04 Thread Joost Yervante Damad
On Wednesday 03 December 2008 21:53:49 Steffen Joeris wrote: > Please go ahead. > > Next time a debdiff would be nice, but I do not have a problem to filter it > out of the upload for testing-security. Here is a debdiff. I have to re-upload, I assumed I didn't have to do a -sa upload, but apparen

Bug#506741: wireshark: DoS caused by sending a SMTP request with large content

2008-12-03 Thread Steffen Joeris
On Wed, 3 Dec 2008 07:55:42 pm Joost Yervante Damad wrote: > On Wednesday 03 December 2008 15:10:12 Frederic Peters wrote: > > Mark Purcell wrote: > > > On Monday 24 November 2008 22:58:38 Steffen Joeris wrote: > > > > Packages for lenny and sid build fine with the patch, I haven't > > > > tested t

Bug#506741: wireshark: DoS caused by sending a SMTP request with large content

2008-12-03 Thread Joost Yervante Damad
On Wednesday 03 December 2008 15:10:12 Frederic Peters wrote: > Mark Purcell wrote: > > On Monday 24 November 2008 22:58:38 Steffen Joeris wrote: > > > Packages for lenny and sid build fine with the patch, I haven't tested > > > them though. Could you get back to me wrt fixes for lenny? > > > > Fre

Bug#506741: wireshark: DoS caused by sending a SMTP request with large content

2008-12-03 Thread Frederic Peters
Mark Purcell wrote: > On Monday 24 November 2008 22:58:38 Steffen Joeris wrote: > > Packages for lenny and sid build fine with the patch, I haven't tested them > > though. Could you get back to me wrt fixes for lenny? > > Frederic, Joost, > > This RC bug, with patch, has been filed against your

Bug#506741: wireshark: DoS caused by sending a SMTP request with large content

2008-12-03 Thread Mark Purcell
On Monday 24 November 2008 22:58:38 Steffen Joeris wrote: > Packages for lenny and sid build fine with the patch, I haven't tested them > though. Could you get back to me wrt fixes for lenny? Frederic, Joost, This RC bug, with patch, has been filed against your package for over a week without a

Bug#506741: wireshark: DoS caused by sending a SMTP request with large content

2008-11-24 Thread Steffen Joeris
Package: wireshark Severity: grave Tags: security, patch Justification: user security hole Hi the following remotely exploitable vulnerability in Wireshark's SMTP dissector has been reported: References: http://packetstormsecurity.org/0811-advisories/wireshark104-dos.txt http://bugs.gentoo.org/sh