1 |
py 07/11/29 21:38:04 |
2 |
|
3 |
Modified: glsa-200711-20.xml |
4 |
Log: |
5 |
Adding second vulnerability and updating versions (#198807) |
6 |
|
7 |
Revision Changes Path |
8 |
1.2 xml/htdocs/security/en/glsa/glsa-200711-20.xml |
9 |
|
10 |
file : http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/security/en/glsa/glsa-200711-20.xml?rev=1.2&view=markup |
11 |
plain: http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/security/en/glsa/glsa-200711-20.xml?rev=1.2&content-type=text/plain |
12 |
diff : http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/security/en/glsa/glsa-200711-20.xml?r1=1.1&r2=1.2 |
13 |
|
14 |
Index: glsa-200711-20.xml |
15 |
=================================================================== |
16 |
RCS file: /var/cvsroot/gentoo/xml/htdocs/security/en/glsa/glsa-200711-20.xml,v |
17 |
retrieving revision 1.1 |
18 |
retrieving revision 1.2 |
19 |
diff -u -r1.1 -r1.2 |
20 |
--- glsa-200711-20.xml 14 Nov 2007 22:08:01 -0000 1.1 |
21 |
+++ glsa-200711-20.xml 29 Nov 2007 21:38:04 -0000 1.2 |
22 |
@@ -4,20 +4,19 @@ |
23 |
<!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd"> |
24 |
|
25 |
<glsa id="200711-20"> |
26 |
- <title>Pioneers: Denial of Service</title> |
27 |
+ <title>Pioneers: Multiple Denials of Service</title> |
28 |
<synopsis> |
29 |
- A vulnerability has been discovered in Pioneers, possibly resulting in a |
30 |
- Denial of Service. |
31 |
+ Two Denial of Service vulnerabilities were discovered in Pioneers. |
32 |
</synopsis> |
33 |
<product type="ebuild">pioneers</product> |
34 |
<announced>November 14, 2007</announced> |
35 |
- <revised>November 14, 2007: 01</revised> |
36 |
+ <revised>November 29, 2007: 04</revised> |
37 |
<bug>198807</bug> |
38 |
<access>remote</access> |
39 |
<affected> |
40 |
<package name="games-board/pioneers" auto="yes" arch="*"> |
41 |
- <unaffected range="ge">0.11.3</unaffected> |
42 |
- <vulnerable range="lt">0.11.3</vulnerable> |
43 |
+ <unaffected range="ge">0.11.3-r1</unaffected> |
44 |
+ <vulnerable range="lt">0.11.3-r1</vulnerable> |
45 |
</package> |
46 |
</affected> |
47 |
<background> |
48 |
@@ -28,9 +27,11 @@ |
49 |
</background> |
50 |
<description> |
51 |
<p> |
52 |
- Bas Wijnen discovered that the Pioneers server may free sessions |
53 |
+ Roland Clobus discovered that the Pioneers server may free sessions |
54 |
objects while they are still in use, resulting in access to invalid |
55 |
- memory zones. |
56 |
+ memory zones (CVE-2007-5933). Bas Wijnen discovered an error when |
57 |
+ closing connections which can lead to a failed assertion |
58 |
+ (CVE-2007-6010). |
59 |
</p> |
60 |
</description> |
61 |
<impact type="normal"> |
62 |
@@ -50,10 +51,11 @@ |
63 |
</p> |
64 |
<code> |
65 |
# emerge --sync |
66 |
- # emerge --ask --oneshot --verbose ">=games-board/pioneers-0.11.3"</code> |
67 |
+ # emerge --ask --oneshot --verbose ">=games-board/pioneers-0.11.3-r1"</code> |
68 |
</resolution> |
69 |
<references> |
70 |
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5933">CVE-2007-5933</uri> |
71 |
+ <uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6010">CVE-2007-6010</uri> |
72 |
</references> |
73 |
<metadata tag="requester" timestamp="Sun, 11 Nov 2007 15:28:52 +0000"> |
74 |
rbu |
75 |
|
76 |
|
77 |
|
78 |
-- |
79 |
gentoo-commits@g.o mailing list |