Comment 4 for bug 256621

Revision history for this message
Thierry Carrez (ttx) wrote :

To fix this in hardy (rc7-based, probably affected) :

Difficult to extract a minimal patch from the RC8 to RC9 diff. I removed what was obviously windowsish and the version number updates. The problem is that the exact nature of the vulnerability doesn't seem to have been disclosed, that the upstream fix is introducing behavioral changes and that the real fix is drowned in a sea of security hardening efforts. What we are looking for must be in route.c, lladdr.c, maybe in multi.c...

I'll try to get more info from upstream.