From owner-freebsd-security@FreeBSD.ORG Sun May 15 20:56:31 2005 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9581416A4CE for ; Sun, 15 May 2005 20:56:31 +0000 (GMT) Received: from mxfep01.bredband.com (mxfep01.bredband.com [195.54.107.70]) by mx1.FreeBSD.org (Postfix) with ESMTP id B29B343D6B for ; Sun, 15 May 2005 20:56:25 +0000 (GMT) (envelope-from jesper@hackunite.net) Received: from mail.hackunite.net ([213.112.198.142] [213.112.198.142]) by mxfep01.bredband.com with ESMTP <20050515205624.XNTU24425.mxfep01.bredband.com@mail.hackunite.net> for ; Sun, 15 May 2005 22:56:24 +0200 Received: from [213.112.198.234] (c-eac670d5.022-45-6f72652.cust.bredbandsbolaget.se [213.112.198.234]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.hackunite.net (Postfix) with ESMTP id A8A4E61A3 for ; Sun, 15 May 2005 22:56:51 +0200 (CEST) Message-ID: <4287B750.6050301@hackunite.net> Date: Sun, 15 May 2005 22:55:44 +0200 From: Jesper Wallin User-Agent: Mozilla Thunderbird 1.0.2 (Windows/20050317) X-Accept-Language: en-us, en MIME-Version: 1.0 To: freebsd-security@freebsd.org Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: amavisd-new at mail.hackunite.net Subject: About the vulnerabilities in tcpdump and gzip. X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 15 May 2005 20:56:31 -0000 Dear list, About a week ago, right after 5.4-RELEASE was released, I received a mail from Gentoo Linux's security announcement list about a flaw in tcpdump and gzip. Since none of them are operating system related, I assumed a -p1 and -p2 of the 5.4-RELEASE. Instead, we got a patch for the HTT security issue so I wonder, is the FreeBSD version of tcpdump and/or gzip are secured or simply forgotten/ignored? tcpdump references: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2005-1279 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2005-1280 gzip references: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0758 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0988 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1228 Best regards, Jesper Wallin