[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-05-29 Thread Bug Watch Updater
** Changed in: libapache-mod-auth-kerb (Debian) Status: Confirmed => Fix Released -- remote heap buffer overflow DoS/code exec https://bugs.launchpad.net/bugs/78486 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-27 Thread Martin Jürgens
** Changed in: libapache-mod-auth-kerb (Ubuntu Edgy) Status: Fix Committed => Fix Released ** Changed in: libapache-mod-auth-kerb (Ubuntu Dapper) Status: Fix Committed => Fix Released ** Changed in: libapache-mod-auth-kerb (Ubuntu Breezy) Status: Fix Committed => Fix Released

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-22 Thread Kees Cook
** Changed in: libapache-mod-auth-kerb (Ubuntu Edgy) Status: Unconfirmed => Fix Committed ** Changed in: libapache-mod-auth-kerb (Ubuntu Dapper) Status: Unconfirmed => Fix Committed ** Changed in: libapache-mod-auth-kerb (Ubuntu Breezy) Status: Unconfirmed => Fix Committed -

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-22 Thread Kees Cook
Great! These look good, thanks. Don't worry about setting "urgency"; Ubuntu doesn't actually use that field yet. I'm building them now, and I'll get them published shortly. -- remote heap buffer overflow DoS/code exec https://launchpad.net/bugs/78486 -- ubuntu-bugs mailing list ubuntu-bugs@l

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-19 Thread Michael Bienia
Here is an updated debdiff for edgy as the last didn't fix the FTBFS. It now has the fix for the FTBFS backported from feisty. ** Attachment added: "debdiff for edgy" http://librarian.launchpad.net/5800722/edgy-debdiff -- remote heap buffer overflow DoS/code exec https://launchpad.net/bugs/78

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-19 Thread Michael Bienia
Here is a debdiff for dapper. ** Attachment added: "debdiff for dapper" http://librarian.launchpad.net/5799772/dapper-debdiff -- remote heap buffer overflow DoS/code exec https://launchpad.net/bugs/78486 -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailm

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-19 Thread Michael Bienia
Here is a debdiff for breezy. ** Attachment added: "debdiff for breezy" http://librarian.launchpad.net/5799773/breezy-debdiff -- remote heap buffer overflow DoS/code exec https://launchpad.net/bugs/78486 -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailm

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-19 Thread Michael Bienia
I could only test if the package for edgy builds. As I've no pbuilder for dapper and breezy anymore I couldn't test the build for those. -- remote heap buffer overflow DoS/code exec https://launchpad.net/bugs/78486 -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.c

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-19 Thread Michael Bienia
Here is a debdiff for edgy. ** Attachment added: "debdiff for edgy" http://librarian.launchpad.net/5799771/edgy-debdiff -- remote heap buffer overflow DoS/code exec https://launchpad.net/bugs/78486 -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/li

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-19 Thread Michael Bienia
Here is a patch extracted from DSA-1247-1: --- libapache-mod-auth-kerb-4.996-5.0-rc6.orig/spnegokrb5/der_get.c +++ libapache-mod-auth-kerb-4.996-5.0-rc6/spnegokrb5/der_get.c @@ -151,7 +151,7 @@ if (len < 1) return ASN1_OVERRUN; -data->components = malloc(len * sizeof(*data->comp

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-09 Thread Bug Watch Updater
** Changed in: libapache-mod-auth-kerb (Debian) Status: Unknown => Confirmed -- remote heap buffer overflow DoS/code exec https://launchpad.net/bugs/78486 -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 78486] Re: remote heap buffer overflow DoS/code exec

2007-01-08 Thread Kees Cook
Version 5.3-1, in Feisty, is not vulnerable. ** Changed in: libapache-mod-auth-kerb (Ubuntu) Status: Unconfirmed => Rejected -- remote heap buffer overflow DoS/code exec https://launchpad.net/bugs/78486 -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/ma