Snort mailing list archives
RE: Two items that are hard to digest...
From: "Michael Steele" <michaels () silicondefense com>
Date: Thu, 17 Apr 2003 09:46:02 -0700
Matt, As far as I know there is no plan to patch 1.9.1. Can someone clarify this? Will there be a patched 1.9.1 made available, and when. I'm assuming that there is at least 1 or 2 Snort users that for whatever reason cannot update to 2.0 at this time. They are very susceptible to this vulnerability. Even the so called fix needs a fix. To be realistic, I'm betting there are more then 1 or 2 Snort 1.9.1 users out there. -Michael -- Michael Steele | System Engineer / Support Technician mailto:michaels () silicondefense com Silicon Defense - The Cyber-War Defense Company Website: http://www.silicondefense.com Snort: Open Source Network IDS - http://www.snort.org -----Original Message----- From: Matt Kettler [mailto:mkettler () evi-inc com] Sent: Thursday, April 17, 2003 9:34 AM To: Michael Steele Cc: snort-users () lists sourceforge net At 09:16 AM 4/17/2003 -0700, Michael Steele wrote:
Matt, Go to http://www.snort.org and read the "Snort Advisory: Integer Overflow
in
Stream4". This needs to be patched in 1.9.1. I saw a post somewhere that there is an unofficial patch floating around, but we need one that is official and available on Snort.org.
Ahh, missed that.. I'd suspect the snort-devels are focusing on making sure 2.0 is stable, and then will backport this a bit later. It's only been a bit under 24 hours, so I'm not too surprised that a patch for 1.9.1 wasn't out the second the vulnerability was detected.... I also suspect that this bug was detected during 2.0 development, and caused for a hastier-than-normal 2.0 release. Personally I'd rather they at least release _some_ fixed version as soon as possible rather than delaying releasing any fix at all until both branches are fixed. I would however agree that a patch for 1.9.x should be released. ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Clarification: Two items that are hard to digest..., (continued)
- Clarification: Two items that are hard to digest... Michael Steele (Apr 17)
- Re: Clarification: Two items that are hard to digest... Matt Kettler (Apr 17)
- Re: Where's Waldo^H^H^H^H^HErek Erek Adams (Apr 21)
- Re: Re: Where's Waldo^H^H^H^H^HErek David Alonso De La Vega Tapage (Apr 21)
- RE: Two items that are hard to digest... Michael Steele (Apr 17)
- RE: Two items that are hard to digest... Michael Steele (Apr 17)
- RE: Two items that are hard to digest... Matt Kettler (Apr 17)
- RE: Two items that are hard to digest... Michael Steele (Apr 17)
- Re: Two items that are hard to digest... Erick Mechler (Apr 17)