Subject: CVS commit: [pkgsrc-2005Q3] pkgsrc/net/ethereal
To: None <pkgsrc-changes@NetBSD.org>
From: Soren Jacobsen <snj@netbsd.org>
List: pkgsrc-changes
Date: 12/10/2005 23:40:58
Module Name: pkgsrc
Committed By: snj
Date: Sat Dec 10 23:40:58 UTC 2005
Modified Files:
pkgsrc/net/ethereal [pkgsrc-2005Q3]: Makefile distinfo
Added Files:
pkgsrc/net/ethereal/patches [pkgsrc-2005Q3]: patch-ac
Log Message:
Pullup ticket 950 - requested by Lubomir Sedlacik
security fix for ethereal
Revisions pulled up:
- pkgsrc/net/ethereal/Makefile 1.121
- pkgsrc/net/ethereal/distinfo 1.46
- pkgsrc/net/ethereal/patches/patch-ac 1.5
Modified Files:
pkgsrc/net/ethereal: Makefile distinfo
Added Files:
pkgsrc/net/ethereal/patches: patch-ac
Log Message:
Security fix for CVE-2005-3651:
"Remote exploitation of an input validation vulnerability in the OSPF
protocol dissectors within Ethereal, as included in various vendors
operating system distributions, could allow attackers to crash the
vulnerable process or potentially execute arbitrary code."
http://www.idefense.com/application/poi/display?id=349&type=vulnerabilities
Patch from the Ethereal SVN repository.
To generate a diff of this commit:
cvs rdiff -r1.115.2.2 -r1.115.2.3 pkgsrc/net/ethereal/Makefile
cvs rdiff -r1.42.2.2 -r1.42.2.3 pkgsrc/net/ethereal/distinfo
cvs rdiff -r0 -r1.3.2.2 pkgsrc/net/ethereal/patches/patch-ac
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.