Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Snort 1.9.1 vulnerabilities.
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
stian@barmen.nu
n00b
n00b


Joined: 12 Jun 2002
Posts: 19

PostPosted: Thu Apr 03, 2003 8:48 am    Post subject: Snort 1.9.1 vulnerabilities. Reply with quote

Snort 1.9.1 seems to have a few security problems reported on securityfous.com. Sadly I am not too much of an ebuild builder so I urge whomever that know how and can find the time to make a build of the 2.0. rc2 which has these issues sorted.

Hope someone can help me! :)
_________________
Best regards
Stian B. Barmen
Back to top
View user's profile Send private message
jasonm
Tux's lil' helper
Tux's lil' helper


Joined: 25 Feb 2003
Posts: 90
Location: Calgary, Canada... Eh!

PostPosted: Thu Apr 03, 2003 9:24 am    Post subject: Reply with quote

I myself don't know much about it. Perhaps you should report it as a bug. Someone on the dev team may know how to fix it.
_________________
Registered User # 323863
There is nothing new under the sun . . .

"Open source takes the bullshit out of software."
[small]~ Charles Ferguson on TechnologyReview.com[/small]
Back to top
View user's profile Send private message
wolf31o2
Retired Dev
Retired Dev


Joined: 31 Jan 2003
Posts: 628
Location: Mountain View, CA

PostPosted: Thu Apr 03, 2003 3:01 pm    Post subject: Reply with quote

Are you sure the patches needed have not already been applied to 1.9.1 int eh newest ebuild? Many times, when a security patch comes along, it is added inline into the current version and the revision number is upped.

For example snort-1.9.1 and snort-1.9.1-r1 are different, the r1 probably includes fixes and patches. This is similar to how many distributions, such as Red Hat, include patches. Many times a program will report that it is a vulnerable version number, but if you look into the code, you will see that it has already been patched.
Back to top
View user's profile Send private message
stian@barmen.nu
n00b
n00b


Joined: 12 Jun 2002
Posts: 19

PostPosted: Fri Apr 04, 2003 7:46 am    Post subject: Reply with quote

I have seen in the Changelog that Daniel Ahlberg har patched it on the 4th of March, but the voulnerabilities was reportet on the 28th of March. After this there has been done what is called "patch and bump revision for alpha" on the 29th of March, but I can't see that this helps any.

Still my urge is out there .. ! (I will report a bug ...!)
_________________
Best regards
Stian B. Barmen
Back to top
View user's profile Send private message
ir0nkid
n00b
n00b


Joined: 28 Feb 2003
Posts: 3
Location: anytown, usa

PostPosted: Wed Apr 16, 2003 9:05 am    Post subject: snort 2.0 Reply with quote

Yes, i have been watching

# emerge sync
# emerge -pv snort

But it's still at 1.9.1-r1. I believe the newest vulnerabilites (telnet decode preprosesor) have not been patched yet. Another thing, i was told that snort 1.9.1 is supposed to include the keywork byte_test in the rules, but i get an error on any rule that contains byte_test still. This would also be fixed if snort-v2 was ready for portage, and i think they have officially released 2.0 also :)
Back to top
View user's profile Send private message
stian@barmen.nu
n00b
n00b


Joined: 12 Jun 2002
Posts: 19

PostPosted: Wed Apr 16, 2003 9:08 am    Post subject: Reply with quote

It seems that hey are looking into it now. Just got a reply from my bug report. We can see a few days.

-stian
_________________
Best regards
Stian B. Barmen
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum