TSLSA-2002-0055 - tcpdump

From: Trustix Secure Linux Advisor (tslat_private)
Date: Thu Jun 06 2002 - 07:05:32 PDT

  • Next message: Ken Brown: "Possible problems with patch MS02_025 for Exchange 2000"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - --------------------------------------------------------------------------
    Trustix Secure Linux Security Advisory #2002-0055
    
    Package name:      tcpdump
    Summary:           Minor bugfix
    Date:              2002-06-05
    Affected versions: TSL 1.1, 1.2, 1.5
    
    - --------------------------------------------------------------------------
    
    Problem description:
      The old tcpdump-packages included a buffer overflow that could be triggered 
      when tracing the network by a bad NFS packet.
      
      We have updated the tcpdump package in TSL-1.1 through 1.5, and hva done some
      additional modifications in TSL-1.1 and 1.2:
    
      The old tcpdump source package also built the libpcap and arpwatch binary 
      packages. We feel this setup is not needed, and have added both libpcap and 
      arpwatch as independable source packages, as done in TSL-1.5.
    
      Due to serial being set in the old TSL-1.1 and 1.2 tcpdump packages, you must
      upgrade the libpcap, and arpwatch packages manually, using the following:
    
      rpm -Uvh --oldpackage [new-package]
    
      Note that this is not necessary when upgrading TSL-1.5
    
    
    Action:
      We recommend that all systems with this package installed are upgraded.
    
    
    Location:
      All TSL updates are available from
      <URI:http://www.trustix.net/pub/Trustix/updates/>
      <URI:ftp://ftp.trustix.net/pub/Trustix/updates/>
    
    
    Automatic updates:
      Users of the SWUP tool can enjoy having updates automatically
      installed using 'swup --upgrade'.
    
      Get SWUP from:
      <URI:ftp://ftp.trustix.net/pub/Trustix/software/swup/>
    
    
    Public testing:
      These packages have been available for public testing for some time.
      If you want to contribute by testing the various packages in the
      testing tree, please feel free to share your findings on the
      tsl-discuss mailinglist.
      The testing tree is located at
      <URI:http://www.trustix.net/pub/Trustix/testing/>
      <URI:ftp://ftp.trustix.net/pub/Trustix/testing/>
      
    
    Questions?
      Check out our mailing lists:
      <URI:http://www.trustix.net/support/>
    
    
    Verification:
      This advisory along with all TSL packages are signed with the TSL sign key.
      This key is available from:
      <URI:http://www.trustix.net/TSL-GPG-KEY>
    
      The advisory itself is available from the errata pages at
      <URI:http://www.trustix.net/errata/trustix-1.2/> and
      <URI:http://www.trustix.net/errata/trustix-1.5/>
      or directly at
      <URI:http://www.trustix.net/errata/misc/2002/TSL-2002-0055-tcpdump.asc.txt>
    
    
    MD5sums of the packages:
    - --------------------------------------------------------------------------
    acabb1cddbd7c46b214b9467249a890e  ./1.5/SRPMS/tcpdump-3.6.2-3tr.src.rpm
    45a90826509143075a37897b6d82cbd7  ./1.5/RPMS/tcpdump-3.6.2-3tr.i586.rpm
    acabb1cddbd7c46b214b9467249a890e  ./1.2/SRPMS/tcpdump-3.6.2-3tr.src.rpm
    dd6aae44a1c99d77fd2ecb9b6ed1320d  ./1.2/RPMS/tcpdump-3.6.2-3tr.i586.rpm
    acabb1cddbd7c46b214b9467249a890e  ./1.1/SRPMS/tcpdump-3.6.2-3tr.src.rpm
    d6defec55c519d712ea4b35f102a8035  ./1.1/RPMS/tcpdump-3.6.2-3tr.i586.rpm
    80ead6877b5c9a90ee54054848dc29d3  ./1.2/SRPMS/libpcap-0.6.2-1tr.src.rpm
    7063d2c28c2a73f98c77778a4bdd78ee  ./1.2/RPMS/libpcap-0.6.2-1tr.i586.rpm
    80ead6877b5c9a90ee54054848dc29d3  ./1.1/SRPMS/libpcap-0.6.2-1tr.src.rpm
    8de56f4d92bb3527171a8d7dc3781aab  ./1.1/RPMS/libpcap-0.6.2-1tr.i586.rpm
    6aab148bfa2b2318eb1e66662ab706b7  ./1.2/SRPMS/arpwatch-2.1a11-1tr.src.rpm
    7e24da863e061c85960cdccce09ebb75  ./1.2/RPMS/arpwatch-2.1a11-1tr.i586.rpm
    6aab148bfa2b2318eb1e66662ab706b7  ./1.1/SRPMS/arpwatch-2.1a11-1tr.src.rpm
    21abbb29c15780184a483b2d73935984  ./1.1/RPMS/arpwatch-2.1a11-1tr.i586.rpm
    - --------------------------------------------------------------------------
    
    
    Trustix Security Team
    
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org
    
    iD8DBQE8/1UiwRTcg4BxxS0RAtfxAJwPkbA7jOaVsM0j2dq0ibgBG09DQgCeNTvM
    KjDXjkB1Z1O7V0+esMBykF4=
    =9y+v
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Thu Jun 06 2002 - 13:42:48 PDT