tcpdump mailing list archives

Re: tcpdump 3.7.2 and libpcap 0.7.2 released


From: "Ademar de Souza Reis Jr." <ademar () conectiva com br>
Date: Mon, 10 Mar 2003 18:02:38 -0300

On Mon, Mar 10, 2003 at 10:30:47AM -0800, Bill Fenner wrote:

Do these security problems also affect tcpdump 3.6.2?

Very likely, yes.

If yes, do you have plans on a new release for 3.6.x?

Not at this time.  We should be focusing on the 3.8 release.
I think a 3.6.x release now would be misleading, since we don't
have time to comb through all the security fixes that were in
3.7, so I think it'd be better to declare the 3.6 branch dead.
(After all, 3.7.1 is over a year old at this point.)


Ok. Just in case, I'm attaching a backport to 3.6.2 of what I
found as being the latest security fixes (from 3.7.2)... Maybe
it's useful to someone else. :) (I also have afsprintting.patch
and snaplen.patch being applied to 3.6.2).

The diff is against the "tcpdump_3_6rel3" CVS tag and
is not tested yet.

-- 
Ademar de Souza Reis Jr. <ademar () conectiva com br>

^[:wq!

Attachment: tcpdump-3.6.2-secfixes_from_3.7.2.patch
Description:


Current thread: