Subject: tcpdump issue matter to NetBSD?
To: None <tech-security@netbsd.org>
From: Jeremy C. Reed <reed@reedmedia.net>
List: tech-security
Date: 03/14/2003 10:44:29
Does the February tcpdump issue matter to NetBSD?

 http://www.idefense.com/advisory/02.27.03.txt
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0108

This is fixed in revision 1.34 (tcpdump's numbers not NetBSD's) of
print-isakmp.c.

I don't see src/dist/tcpdump/print-isakmp.c updated. The one included with
NetBSD is 1.29 (tcpdump's revision number).

And pkgsrc/net/tcpdump is out-of-date too.

Also, according to advisory tcpdump 3.7.2 includes other security fixes.

   Jeremy C. Reed
   http://bsd.reedmedia.net/