From 8d8a1b6e3bef6dcb19aafb9d796688e7af1638b5f7e3daff7a8d28f98c5e7acd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Chv=C3=A1tal?= Date: Thu, 2 Feb 2017 16:04:10 +0000 Subject: [PATCH] Accepting request 454244 from home:pmonrealgonzalez:branches:network:utilities - version update to 4.9.0 bsc#1020940 * CVE-2016-7922 The AH parser in tcpdump before 4.9.0 has a buffer overflow in print-ah.c:ah_print(). * CVE-2016-7923 The ARP parser in tcpdump before 4.9.0 has a buffer overflow in print-arp.c:arp_print(). * CVE-2016-7924 The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:oam_print(). * CVE-2016-7925 The compressed SLIP parser in tcpdump before 4.9.0 has a buffer overflow in print-sl.c:sl_if_print(). * CVE-2016-7926 The Ethernet parser in tcpdump before 4.9.0 has a buffer overflow in print-ether.c:ethertype_print(). * CVE-2016-7927 The IEEE 802.11 parser in tcpdump before 4.9.0 has a buffer overflow in print-802_11.c:ieee802_11_radio_print(). * CVE-2016-7928 The IPComp parser in tcpdump before 4.9.0 has a buffer overflow in print-ipcomp.c:ipcomp_print(). * CVE-2016-7929 The Juniper PPPoE ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-juniper.c:juniper_parse_header(). * CVE-2016-7930 The LLC parser in tcpdump before 4.9.0 has a buffer overflow in print-llc.c:llc_print(). * CVE-2016-7931 The MPLS parser in tcpdump before 4.9.0 has a buffer overflow in print-mpls.c:mpls_print(). * CVE-2016-7932 The PIM parser in tcpdump before 4.9.0 has a buffer overflow in print-pim.c:pimv2_check_checksum(). * CVE-2016-7933 The PPP parser in tcpdump before 4.9.0 has a buffer overflow in print-ppp.c:ppp_hdlc_if_print(). * CVE-2016-7934 The RTCP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtcp_print(). * CVE-2016-7935 The RTP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtp_print(). * CVE-2016-7936 The UDP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:udp_print(). * CVE-2016-7937 The VAT parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:vat_print(). * CVE-2016-7938 The ZeroMQ parser in tcpdump before 4.9.0 has an integer overflow in print-zeromq.c:zmtp1_print_frame(). * CVE-2016-7939 The GRE parser in tcpdump before 4.9.0 has a buffer overflow in print-gre.c, multiple functions. * CVE-2016-7940 The STP parser in tcpdump before 4.9.0 has a buffer overflow in print-stp.c, multiple functions. * CVE-2016-7973 The AppleTalk parser in tcpdump before 4.9.0 has a buffer overflow in print-atalk.c, multiple functions. * CVE-2016-7974 The IP parser in tcpdump before 4.9.0 has a buffer overflow in print-ip.c, multiple functions. * CVE-2016-7975 The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print(). * CVE-2016-7983 The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print(). * CVE-2016-7984 The TFTP parser in tcpdump before 4.9.0 has a buffer overflow in print-tftp.c:tftp_print(). * CVE-2016-7985 The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print(). * CVE-2016-7986 The GeoNetworking parser in tcpdump before 4.9.0 has a buffer overflow in print-geonet.c, multiple functions. * CVE-2016-7992 The Classical IP over ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-cip.c:cip_if_print(). * CVE-2016-7993 A bug in util-print.c:relts_print() could cause a buffer overflow in multiple protocol parsers (DNS, DVMRP, HSRP, IGMP, lightweight resolver protocol, PIM). * CVE-2016-8574 The FRF.15 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:frf15_print(). OBS-URL: https://build.opensuse.org/request/show/454244 OBS-URL: https://build.opensuse.org/package/show/network:utilities/tcpdump?expand=0&rev=35 --- tcpdump-4.7.4.tar.gz | 3 --- tcpdump-4.7.4.tar.gz.sig | Bin 419 -> 0 bytes tcpdump-4.9.0.tar.gz | 3 +++ tcpdump-4.9.0.tar.gz.sig | Bin 0 -> 442 bytes tcpdump.changes | 46 +++++++++++++++++++++++++++++++++++++++ tcpdump.spec | 12 +++++----- 6 files changed, 54 insertions(+), 10 deletions(-) delete mode 100644 tcpdump-4.7.4.tar.gz delete mode 100644 tcpdump-4.7.4.tar.gz.sig create mode 100644 tcpdump-4.9.0.tar.gz create mode 100644 tcpdump-4.9.0.tar.gz.sig diff --git a/tcpdump-4.7.4.tar.gz b/tcpdump-4.7.4.tar.gz deleted file mode 100644 index 89ff04e..0000000 --- a/tcpdump-4.7.4.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:6be520269a89036f99c0b2126713a60965953eab921002b07608ccfc0c47d9af -size 1153657 diff --git a/tcpdump-4.7.4.tar.gz.sig b/tcpdump-4.7.4.tar.gz.sig deleted file mode 100644 index d68619ee4a58e294051d3150d3a1416b1bd0c8acdf380eb63f1448dcec43ad63..0000000000000000000000000000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 419 zcmV;U0bKrx0iXl`0RjL91p-w#2LS*I2@v3k-tpPNT@4og3?S9FSVcsqTe61|53k_K zy-JW1Wv(h$V?Sgbb1Utt#?DBoG*%E0m-YSzctwaMy|WJVZUhlhPBhAaWHs{dL-ioh zlW3g{sBlai@zSUgxZc4-t{jt>VAg8qn6+orT1g&&o#M%0Txn{euOh_{4YBHHKdMwdLH9aJWCZlV7P=We=!kf#j5CfOZ{1+w z=xV$jKWkaf@}^j%v-;&^#ryevwfbbBF7!UyHazZ_2J$E<7|ZboGVNuUT70cM%kcDt Nh3Fsn&B~F~l+aO@%v1mX diff --git a/tcpdump-4.9.0.tar.gz b/tcpdump-4.9.0.tar.gz new file mode 100644 index 0000000..67662c5 --- /dev/null +++ b/tcpdump-4.9.0.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:eae98121cbb1c9adbedd9a777bf2eae9fa1c1c676424a54740311c8abcee5a5e +size 1260309 diff --git a/tcpdump-4.9.0.tar.gz.sig b/tcpdump-4.9.0.tar.gz.sig new file mode 100644 index 0000000000000000000000000000000000000000000000000000000000000000..ba789850d817e21469975fb2759b412695bea4b7b029f44a23d2108d462cad33 GIT binary patch literal 442 zcmV;r0Y(0a0k;GI0SEvc79j*57HU^QtGVDLnvF2viQe(q!Cegn0$7Km@&F165a5a4 z@!7#$4WMoe9TbHvy}k|W_&=dlhDi3)S8L=Q&5e72{Ju9Fk&0!(!|&t|Y@xvGLxAts zFxBdz=C6K=*mmUl%%Jde&vkB(Qhd^*4n&YIeyoeX7kM&*Hw!E(Wm8h657yy#R+G24 zYCJ!rYMq%;fwp39Ajl1A&1|ai*!;_jjtUTr(BviNgDU>=0zG+Dd16xDcPWRG_cov* znvCQ|io&j$z-}f{_qNO9v|u$CFi$)#0n15NApZBtU7#RFTTErAmB)T6Q4}>(Q|q#r zIU_EjaXU{oIlpw7#?5U|Cdi~*?y@O>rSDDrA3Yi#C6u$+>snzL0N)sxM;W+Ck8)wh z1to^>M(f2cV1?iL#xqqX?3e`az88RHu+o-RZZ&;<(pXA*M?c4%%Dr=S*KaUwf0wu9 z;V1Ahw5|DI;+Ixk#f!D>M_AqC-^3=-Ih>22EUKMSSA|y1)&>4rjLWrFMZaIaPJh`0 kU>hs(Wrwk#*P|<@kAz$+P!7HT%HF^s)Oi1}M