Processed: Re: Bug#900967: Security vulnerability: Stack overflow in BGP mask expressions

2018-06-08 Thread Debian Bug Tracking System
Processing control commands: > retitle -1 bird: CVE-2018-12066: Stack overflow in BGP mask expressions Bug #900967 [src:bird] Security vulnerability: Stack overflow in BGP mask expressions Changed Bug title to 'bird: CVE-2018-12066: Stack overflow in BGP mask expressions' from 'Security vulnerab

Bug#900967: Security vulnerability: Stack overflow in BGP mask expressions

2018-06-08 Thread Salvatore Bonaccorso
Control: retitle -1 bird: CVE-2018-12066: Stack overflow in BGP mask expressions CVE-2018-12066 was assigned by MITRE for the mentioned issue. Regards, Salvatore

Bug#900967: Security vulnerability: Stack overflow in BGP mask expressions

2018-06-08 Thread Moritz Muehlenhoff
On Thu, Jun 07, 2018 at 11:34:15PM +0200, Ondrej Zajicek wrote: > On Thu, Jun 07, 2018 at 10:48:10PM +0200, Moritz Muehlenhoff wrote: > > > Hi > > > > > > It is an security bugfix, but perhaps not so critical, it can be > > > exploited in very specific circumstances and probably only as a DoS, > >

Bug#900967: Security vulnerability: Stack overflow in BGP mask expressions

2018-06-07 Thread Ondrej Zajicek
On Thu, Jun 07, 2018 at 10:48:10PM +0200, Moritz Muehlenhoff wrote: > > Hi > > > > It is an security bugfix, but perhaps not so critical, it can be > > exploited in very specific circumstances and probably only as a DoS, > > not as a privilege escalation. > > I'm not familiar with bird, so we cou

Bug#900967: Security vulnerability: Stack overflow in BGP mask expressions

2018-06-07 Thread Moritz Muehlenhoff
B0;115;0cOn Thu, Jun 07, 2018 at 08:27:22PM +0200, Ondrej Zajicek wrote: > On Thu, Jun 07, 2018 at 01:37:04PM +0200, Jonas Meurer wrote: > > Source: bird > > Version: 1.6.3-2 > > Severity: critical > > Tags: security > > > > According to the upstream website[1] and changelog[2], bird release 1.6.4

Bug#900967: Security vulnerability: Stack overflow in BGP mask expressions

2018-06-07 Thread Ondrej Zajicek
On Thu, Jun 07, 2018 at 01:37:04PM +0200, Jonas Meurer wrote: > Source: bird > Version: 1.6.3-2 > Severity: critical > Tags: security > > According to the upstream website[1] and changelog[2], bird release 1.6.4 > includes an "important security bugfix". Hi It is an security bugfix, but perhaps

Bug#900967: Security vulnerability: Stack overflow in BGP mask expressions

2018-06-07 Thread Jonas Meurer
Source: bird Version: 1.6.3-2 Severity: critical Tags: security According to the upstream website[1] and changelog[2], bird release 1.6.4 includes an "important security bugfix". The changelog mentions "Filter: Fixed stack overflow in BGP mask expressions". A quick scan through the git history re