Gentoo Archives: gentoo-announce

From: Thierry Carrez <koon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200509-14 ] Zebedee: Denial of Service vulnerability
Date: Tue, 20 Sep 2005 14:07:31
Message-Id: 4330131D.4060409@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200509-14
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Zebedee: Denial of Service vulnerability
9 Date: September 20, 2005
10 Bugs: #105115
11 ID: 200509-14
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A bug in Zebedee allows a remote attacker to perform a Denial of
19 Service attack.
20
21 Background
22 ==========
23
24 Zebedee is an application that establishes an encrypted, compressed
25 tunnel for TCP/IP or UDP data transfer between two systems.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-misc/zebedee < 2.5.3 *>= 2.4.1-r1
34 >= 2.5.3
35
36 Description
37 ===========
38
39 "Shiraishi.M" reported that Zebedee crashes when "0" is received as the
40 port number in the protocol option header.
41
42 Impact
43 ======
44
45 By performing malformed requests a remote attacker could cause Zebedee
46 to crash.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All Zebedee users should upgrade to the latest version:
57
58 # emerge --sync
59 # emerge --ask --oneshot --verbose net-misc/zebedee
60
61 References
62 ==========
63
64 [ 1 ] BugTraq ID 14796
65 http://www.securityfocus.com/bid/14796
66
67 Availability
68 ============
69
70 This GLSA and any updates to it are available for viewing at
71 the Gentoo Security Website:
72
73 http://security.gentoo.org/glsa/glsa-200509-14.xml
74
75 Concerns?
76 =========
77
78 Security is a primary focus of Gentoo Linux and ensuring the
79 confidentiality and security of our users machines is of utmost
80 importance to us. Any security concerns should be addressed to
81 security@g.o or alternatively, you may file a bug at
82 http://bugs.gentoo.org.
83
84 License
85 =======
86
87 Copyright 2005 Gentoo Foundation, Inc; referenced text
88 belongs to its owner(s).
89
90 The contents of this document are licensed under the
91 Creative Commons - Attribution / Share Alike license.
92
93 http://creativecommons.org/licenses/by-sa/2.0

Attachments

File name MIME type
signature.asc application/pgp-signature