Bug#446354: OpenBSD patch for CVE-2007-5365 is insufficient

2007-10-29 Thread Nico Golde
Hi, * Nico Golde <[EMAIL PROTECTED]> [2007-10-29 22:30]: > * Steve Kemp <[EMAIL PROTECTED]> [2007-10-29 21:59]: > > On Mon Oct 29, 2007 at 19:33:17 +0100, Tomas Hoger wrote: > > > > > During testing of our updated dhcp packages, we have found out that > > > patch for CVE-2007-5365 used by OpenBSD

Bug#446354: OpenBSD patch for CVE-2007-5365 is insufficient

2007-10-29 Thread Nico Golde
Hi Steve, * Steve Kemp <[EMAIL PROTECTED]> [2007-10-29 21:59]: > On Mon Oct 29, 2007 at 19:33:17 +0100, Tomas Hoger wrote: > > > During testing of our updated dhcp packages, we have found out that > > patch for CVE-2007-5365 used by OpenBSD was not sufficient and it was > > still possible to crash

Bug#446354: OpenBSD patch for CVE-2007-5365 is insufficient

2007-10-29 Thread Steve Kemp
On Mon Oct 29, 2007 at 19:33:17 +0100, Tomas Hoger wrote: > During testing of our updated dhcp packages, we have found out that > patch for CVE-2007-5365 used by OpenBSD was not sufficient and it was > still possible to crash dhcpd. Your dhcp packages released in DSA > 1388-1 also seem affected.

Bug#446354: OpenBSD patch for CVE-2007-5365 is insufficient

2007-10-29 Thread Tomas Hoger
Hi! During testing of our updated dhcp packages, we have found out that patch for CVE-2007-5365 used by OpenBSD was not sufficient and it was still possible to crash dhcpd. Your dhcp packages released in DSA 1388-1 also seem affected. You can find better patch based on dhcp-3.x code here: http