CVE-2014-5439: Root shell on Sniffit

Related Vulnerabilities: CVE-2014-5439  

Debian Bug report logs - #845122
CVE-2014-5439: Root shell on Sniffit

version graph

Reported by: Markus Koschany <apo@debian.org>

Date: Sun, 20 Nov 2016 15:06:01 UTC

Severity: grave

Tags: security, upstream

Found in version sniffit/0.3.7.beta-16.1

Fixed in versions 0.3.7.beta-16.1+deb7u1, sniffit/0.4.0-1, sniffit/0.3.7.beta-20

Done: Salvatore Bonaccorso <carnil@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Joao Eriberto Mota Filho <eriberto@debian.org>:
Bug#845122; Package sniffit. (Sun, 20 Nov 2016 15:06:04 GMT) (full text, mbox, link).


Acknowledgement sent to Markus Koschany <apo@debian.org>:
New Bug report received and forwarded. Copy sent to Joao Eriberto Mota Filho <eriberto@debian.org>. (Sun, 20 Nov 2016 15:06:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Markus Koschany <apo@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2014-5439: Root shell on Sniffit
Date: Sun, 20 Nov 2016 16:02:34 +0100
[Message part 1 (text/plain, inline)]
Package: sniffit
Severity: grave
Tags: security
Version: 0.3.7.beta-16.1

Hi,

the following vulnerability was published for sniffit.

CVE-2014-5439[0]:
	Root shell on Sniffit

http://hmarco.org/bugs/CVE-2014-5439-sniffit_0.3.7-stack-buffer-overflow.html

The version in unstable already includes the fix but Testing, Jessie and
Wheezy are still vulnerable.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2014-5439
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5439
Please adjust the affected versions in the BTS as needed.


[signature.asc (application/pgp-signature, attachment)]

Marked as fixed in versions sniffit/0.4.0-1. Request was from Markus Koschany <apo@debian.org> to control@bugs.debian.org. (Sun, 20 Nov 2016 15:09:06 GMT) (full text, mbox, link).


Added tag(s) upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 20 Nov 2016 18:30:06 GMT) (full text, mbox, link).


Marked as fixed in versions sniffit/0.3.7.beta-20. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 20 Nov 2016 18:30:06 GMT) (full text, mbox, link).


Marked Bug as done Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 20 Nov 2016 18:30:07 GMT) (full text, mbox, link).


Notification sent to Markus Koschany <apo@debian.org>:
Bug acknowledged by developer. (Sun, 20 Nov 2016 18:30:08 GMT) (full text, mbox, link).


Message sent on to Markus Koschany <apo@debian.org>:
Bug#845122. (Sun, 20 Nov 2016 18:30:10 GMT) (full text, mbox, link).


Message #18 received at 845122-submitter@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: control@bugs.debian.org
Cc: 845122-submitter@bugs.debian.org
Subject: tagging 845122, closing 845122
Date: Sun, 20 Nov 2016 19:27:25 +0100
tags 845122 + upstream
close 845122 0.3.7.beta-20
thanks




Marked as fixed in versions 0.3.7.beta-16.1+deb7u1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Mon, 21 Nov 2016 18:36:09 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Thu, 29 Dec 2016 07:58:01 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 15:30:33 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.