[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[DEBIAN-LTS] ettercap package



Hi all,

I have created .deb file for ettercap package.
Since I'm not DD or DM so I attached debdiff file for review
as mentioned in LTS/Development wiki page.

Could anyone please check it and tell me if any comments?
I also build .deb file for firebird2.1 and firebird2.5, but may
be I will post it in the next mail

Thanks
CongNT
File lists identical (after any substitutions)

Control files: lines which differ (wdiff format)
------------------------------------------------
Depends: libc6 (>= 2.7), libltdl7 (>= 2.2.6b), libncurses5 (>= 5.7+20100313), libnet1 (>= 1.1.2.1), libpcap0.8 (>= 0.9.8), libpcre3 (>= 7.7), libssl0.9.8 (>= 0.9.8m-1), zlib1g (>= 1:1.1.4), ettercap-common (= [-1:0.7.3-2.1+squeeze1)-] {+1:0.7.3-2.1+squeeze2)+}
Version: [-1:0.7.3-2.1+squeeze1-] {+1:0.7.3-2.1+squeeze2+}
diff -u ettercap-0.7.3/debian/changelog ettercap-0.7.3/debian/changelog
--- ettercap-0.7.3/debian/changelog
+++ ettercap-0.7.3/debian/changelog
@@ -1,3 +1,11 @@
+ettercap (1:0.7.3-2.1+squeeze2) squeeze-lts; urgency=medium
+
+  * Non-maintainer upload.
+  * Fix CVE-2014-9380 and CVE-2014-9381 using patch file from
+    Gianfranco Costamagna in Bug#773416 Mes#20
+
+ -- Nguyen Cong <cong.nguyenthe@toshiba-tsdv.com>  Tue, 23 Dec 2014 09:44:32 +0700
+
 ettercap (1:0.7.3-2.1+squeeze1) stable; urgency=high
 
   * Quilt patch for CVE-2013-0722, a stack-based buffer overflow when
only in patch2:
unchanged:
--- ettercap-0.7.3.orig/src/dissectors/ec_cvs.c
+++ ettercap-0.7.3/src/dissectors/ec_cvs.c
@@ -70,7 +70,7 @@
 {
    DECLARE_DISP_PTR_END(ptr, end);
    char tmp[MAX_ASCII_ADDR_LEN];
-   char *p;
+   u_char *p;
    size_t i;
 
    /* don't complain about unused var */
@@ -92,6 +92,8 @@
    
    /* move over the cvsroot path */
    ptr += strlen(CVS_LOGIN) + 1;
+	if (ptr >= end)
+		return NULL;
 
    /* go until \n */
    while(*ptr != '\n' && ptr != end) ptr++;
Format: 1.8
Date: Tue, 23 Dec 2014 09:44:32 +0700
Source: ettercap
Binary: ettercap-common ettercap ettercap-gtk
Architecture: source i386
Version: 1:0.7.3-2.1+squeeze2
Distribution: squeeze-lts
Urgency: medium
Maintainer: Murat Demirten <murat@debian.org>
Changed-By: Nguyen Cong <cong.nguyenthe@toshiba-tsdv.com>
Description: 
 ettercap   - Multipurpose sniffer/interceptor/logger for switched LAN
 ettercap-common - Common support files and plugins for ettercap
 ettercap-gtk - Multipurpose sniffer/interceptor/logger for switched LAN
Changes: 
 ettercap (1:0.7.3-2.1+squeeze2) squeeze-lts; urgency=medium
 .
   * Non-maintainer upload.
   * Fix CVE-2014-9380 and CVE-2014-9381 using patch file from
     Gianfranco Costamagna in Bug#773416 Mes#20
Checksums-Sha1: 
 683200b381f6440c19b24a8f3403434aa3a422de 942 ettercap_0.7.3-2.1+squeeze2.dsc
 a149f931411a6205f98b25145525648c32bee68d 6781 ettercap_0.7.3-2.1+squeeze2.diff.gz
 9aa764f408207a3fbea32361d3e2806a541b9b1e 304056 ettercap-common_0.7.3-2.1+squeeze2_i386.deb
 a42658dc0c3e0f981d5187a187b731bde321a2c1 190394 ettercap_0.7.3-2.1+squeeze2_i386.deb
 0e63ff63a6f79dad2d5995df15d21e0e48eaef99 227138 ettercap-gtk_0.7.3-2.1+squeeze2_i386.deb
Checksums-Sha256: 
 e7175b2f2f768c1199706aea7089f2880a0d7d247ee9a794dfc811b47b6d5027 942 ettercap_0.7.3-2.1+squeeze2.dsc
 9a70070184891c7348f6dc59bed78650528ba1cb2f96f5010a3bee023b3d4228 6781 ettercap_0.7.3-2.1+squeeze2.diff.gz
 d89a16fbcb981ce120c4dbfa753a62482b6e2d9ca23606359d6015b00c688ac9 304056 ettercap-common_0.7.3-2.1+squeeze2_i386.deb
 3237a58e3b73352c0eaec0a7b8f88ba7494c1c82b26f02210a2e98a9781aac42 190394 ettercap_0.7.3-2.1+squeeze2_i386.deb
 3514e3bb8115285e8730448bbadf61b7f7945ac2c68eac92e77767bc96c6728c 227138 ettercap-gtk_0.7.3-2.1+squeeze2_i386.deb
Files: 
 688506bde5ad78f12d6b4f74f24de905 942 net optional ettercap_0.7.3-2.1+squeeze2.dsc
 60c907874f8c668c7771aeb9ca4d420f 6781 net optional ettercap_0.7.3-2.1+squeeze2.diff.gz
 b3ecdd4ebdea7aa5bea01a3b65c33ab9 304056 net optional ettercap-common_0.7.3-2.1+squeeze2_i386.deb
 a5c51d35237089a30c629e71709afb91 190394 net optional ettercap_0.7.3-2.1+squeeze2_i386.deb
 e511a4c52c390709c60f8acf1d8053f4 227138 net optional ettercap-gtk_0.7.3-2.1+squeeze2_i386.deb

Reply to: