Merge tcpdump 4.6.2-4 (main) from Debian unstable (main)

Bug #1433815 reported by Artur Rona
18
This bug affects 2 people
Affects Status Importance Assigned to Milestone
tcpdump (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

tcpdump (4.6.2-4) unstable; urgency=high

  * Cherry-pick changes from upstream Git to fix the following security
    issues:
    + CVE-2015-0261: missing bounds checks in IPv6 Mobility printer.
    + CVE-2015-2153: missing bounds checks in RPKI/RTR printer.
    + CVE-2015-2154: missing bounds checks in ISOCLNS printer.
    + CVE-2015-2155: missing bounds checks in ForCES printer.

 -- Romain Francoise <email address hidden> Sat, 14 Mar 2015 18:43:44 +0100

Artur Rona (ari-tczew)
Changed in tcpdump (Ubuntu):
importance: Undecided → Medium
status: New → Confirmed
Revision history for this message
Tyler Hicks (tyhicks) wrote :

Hi Artur - Thanks for the debdiffs! It looks like the new 60_cve-2015-2153.diff patch has a regression and possibly isn't complete. See https://github.com/the-tcpdump-group/tcpdump/commit/fb6e5377f392555b8c725f66b8b701f0061a3695 for what looks to be a followup patch.

Revision history for this message
Tyler Hicks (tyhicks) wrote :

The rest of the changes look good and the package passed the modest tests in QRT's test-tcpdump.py.

Changed in tcpdump (Ubuntu):
status: Confirmed → Incomplete
Revision history for this message
Tyler Hicks (tyhicks) wrote :

Also, everything looked good in the output from the security team's umt build tools.

Revision history for this message
Artur Rona (ari-tczew) wrote :
Revision history for this message
Artur Rona (ari-tczew) wrote :
Revision history for this message
Artur Rona (ari-tczew) wrote :

Updated debdiffs with a new patch to fix a regression. Cherry-picked from URL mentioned in comment #3.

Changed in tcpdump (Ubuntu):
status: Incomplete → Confirmed
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

ACK on ubuntu-ubuntu.debdiff. Building now and will upload.

Thanks!

Changed in tcpdump (Ubuntu):
status: Confirmed → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package tcpdump - 4.6.2-4ubuntu1

---------------
tcpdump (4.6.2-4ubuntu1) vivid; urgency=low

  * Merge from Debian unstable. (LP: #1433815) Remaining changes:
    - debian/{control, README.Debian, tcpdump.dirs, usr.sbin.tcpdump,
      install, rules, patches/patches/90_man_apparmor.diff}:
      + Add AppArmor profile.
    - debian/usr.sbin.tcpdump:
      + Allow capability net_admin to support '-j'.
  * debian/patches/60_cve-2015-2153-fix-regression.diff:
    - Fix regression due to 60_cve-2015-2153.diff

tcpdump (4.6.2-4) unstable; urgency=high

  * Cherry-pick changes from upstream Git to fix the following security
    issues:
    + CVE-2015-0261: missing bounds checks in IPv6 Mobility printer.
    + CVE-2015-2153: missing bounds checks in RPKI/RTR printer.
    + CVE-2015-2154: missing bounds checks in ISOCLNS printer.
    + CVE-2015-2155: missing bounds checks in ForCES printer.
 -- Artur Rona <email address hidden> Mon, 23 Mar 2015 00:42:29 +0100

Changed in tcpdump (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.