Gentoo Archives: gentoo-commits

From: "Pierre-Yves Rofes (py)" <py@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] gentoo commit in xml/htdocs/security/en/glsa: glsa-200711-20.xml
Date: Thu, 29 Nov 2007 21:38:20
Message-Id: E1Ixr5A-0004vU-Kt@stork.gentoo.org
1 py 07/11/29 21:38:04
2
3 Modified: glsa-200711-20.xml
4 Log:
5 Adding second vulnerability and updating versions (#198807)
6
7 Revision Changes Path
8 1.2 xml/htdocs/security/en/glsa/glsa-200711-20.xml
9
10 file : http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/security/en/glsa/glsa-200711-20.xml?rev=1.2&view=markup
11 plain: http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/security/en/glsa/glsa-200711-20.xml?rev=1.2&content-type=text/plain
12 diff : http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/security/en/glsa/glsa-200711-20.xml?r1=1.1&r2=1.2
13
14 Index: glsa-200711-20.xml
15 ===================================================================
16 RCS file: /var/cvsroot/gentoo/xml/htdocs/security/en/glsa/glsa-200711-20.xml,v
17 retrieving revision 1.1
18 retrieving revision 1.2
19 diff -u -r1.1 -r1.2
20 --- glsa-200711-20.xml 14 Nov 2007 22:08:01 -0000 1.1
21 +++ glsa-200711-20.xml 29 Nov 2007 21:38:04 -0000 1.2
22 @@ -4,20 +4,19 @@
23 <!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd">
24
25 <glsa id="200711-20">
26 - <title>Pioneers: Denial of Service</title>
27 + <title>Pioneers: Multiple Denials of Service</title>
28 <synopsis>
29 - A vulnerability has been discovered in Pioneers, possibly resulting in a
30 - Denial of Service.
31 + Two Denial of Service vulnerabilities were discovered in Pioneers.
32 </synopsis>
33 <product type="ebuild">pioneers</product>
34 <announced>November 14, 2007</announced>
35 - <revised>November 14, 2007: 01</revised>
36 + <revised>November 29, 2007: 04</revised>
37 <bug>198807</bug>
38 <access>remote</access>
39 <affected>
40 <package name="games-board/pioneers" auto="yes" arch="*">
41 - <unaffected range="ge">0.11.3</unaffected>
42 - <vulnerable range="lt">0.11.3</vulnerable>
43 + <unaffected range="ge">0.11.3-r1</unaffected>
44 + <vulnerable range="lt">0.11.3-r1</vulnerable>
45 </package>
46 </affected>
47 <background>
48 @@ -28,9 +27,11 @@
49 </background>
50 <description>
51 <p>
52 - Bas Wijnen discovered that the Pioneers server may free sessions
53 + Roland Clobus discovered that the Pioneers server may free sessions
54 objects while they are still in use, resulting in access to invalid
55 - memory zones.
56 + memory zones (CVE-2007-5933). Bas Wijnen discovered an error when
57 + closing connections which can lead to a failed assertion
58 + (CVE-2007-6010).
59 </p>
60 </description>
61 <impact type="normal">
62 @@ -50,10 +51,11 @@
63 </p>
64 <code>
65 # emerge --sync
66 - # emerge --ask --oneshot --verbose &quot;&gt;=games-board/pioneers-0.11.3&quot;</code>
67 + # emerge --ask --oneshot --verbose &quot;&gt;=games-board/pioneers-0.11.3-r1&quot;</code>
68 </resolution>
69 <references>
70 <uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5933">CVE-2007-5933</uri>
71 + <uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6010">CVE-2007-6010</uri>
72 </references>
73 <metadata tag="requester" timestamp="Sun, 11 Nov 2007 15:28:52 +0000">
74 rbu
75
76
77
78 --
79 gentoo-commits@g.o mailing list