tags 728144 + moreinfo
thanks

The CVE issues were discovered by crashes remaining after the TZ issue
was resolved. It appears that the TZ issue was one of at least 5
different crashes which could result from the CVE-2014-7142 bug.

Both CVE bugs are confirmed resolved. But that does not mean pinger is
crash-free.

The Ubuntu bug report (and two other open Debian reports about pinger)
contain symptoms from several crash bugs, and some other behaviour.
People seem to be jumping to conclusions that any crash they see is one
or other bug report and adding their details to it without checking to
confirm. The result has been a rather confused mess of fixed and
non-fixed messages.


** The issue Stephan is reporting "IcmpPinger.cc:190 (debugFinish)" is
fixed and confirmed by others.

** The issue Gerald is reporting "IcmpPinger.cc:222 (debugFinish)" may
be the result of the above fix changing line numbers while the CVE
remained open. We need package version details to confirm.

**  The issue Anton is reporting is unidentifiable from the info
provided. "it" being possibly Icmp6.cc related.


Amos


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to