Small specfile improvements to confirm to updated packaging guidelines. Thx to mschwendt. Updated to latest SVN, fixing various bugs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-2638 2015-02-26 17:25:31 -------------------------------------------------------------------------------- Name : echoping Product : Fedora 22 Version : 6.1 Release : 0.1.beta.r434svn.fc22 URL : Summary : TCP performance test to measure response time of network hosts Description : Echoping is a small program to test (approximate) performances of a remote host by sending TCP "echo" (or other protocol, such as HTTP) packets. -------------------------------------------------------------------------------- Update Information: Small specfile improvements to confirm to updated packaging guidelines. Thx to mschwendt. Updated to latest SVN, fixing various bugs. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1007031 - echoping segfaults all the time https://bugzilla.redhat.com/show_bug.cgi?id=1007031 [ 2 ] Bug #1032547 - echoping doesn't seem to work (cannot open shared object file) https://bugzilla.redhat.com/show_bug.cgi?id=1032547 [ 3 ] Bug #705174 - echoping: boundary error in SSL-related functions can lead to buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=705174 [ 4 ] Bug #460557 - echoping : Package and software are in a desolate state https://bugzilla.redhat.com/show_bug.cgi?id=460557 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update echoping' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated to latest SVN, fixing various bugs. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-2600 2015-02-26 02:34:10 -------------------------------------------------------------------------------- Name : echoping Product : Fedora 20 Version : 6.1 Release : 0.beta.r434svn.1.fc20 URL : Summary : TCP performance test to measure response time of network hosts Description : Echoping is a small program to test (approximate) performances of a remote host by sending TCP "echo" (or other protocol, such as HTTP) packets. -------------------------------------------------------------------------------- Update Information: Updated to latest SVN, fixing various bugs -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 25 2015 Andreas Thienemann - 6.1-0.beta.r434svn.1 - Updated to latest SVN, fixing #705174 and #1007031 - Removed so versioning and fixed module loading, fixing #460557 and #1032547 * Sat Aug 16 2014 Fedora Release Engineering - 6.0.2-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Jun 7 2014 Fedora Release Engineering - 6.0.2-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #705174 - echoping: boundary error in SSL-related functions can lead to buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=705174 [ 2 ] Bug #1007031 - echoping segfaults all the time https://bugzilla.redhat.com/show_bug.cgi?id=1007031 [ 3 ] Bug #460557 - echoping : Package and software are in a desolate state https://bugzilla.redhat.com/show_bug.cgi?id=460557 [ 4 ] Bug #1032547 - echoping doesn't seem to work (cannot open shared object file) https://bugzilla.redhat.com/show_bug.cgi?id=1032547 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update echoping' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated to latest SVN, fixing various bugs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-2584 2015-02-26 02:33:37 -------------------------------------------------------------------------------- Name : echoping Product : Fedora 21 Version : 6.1 Release : 0.beta.r434svn.1.fc21 URL : Summary : TCP performance test to measure response time of network hosts Description : Echoping is a small program to test (approximate) performances of a remote host by sending TCP "echo" (or other protocol, such as HTTP) packets. -------------------------------------------------------------------------------- Update Information: Updated to latest SVN, fixing various bugs. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 25 2015 Andreas Thienemann - 6.1-0.beta.r434svn.1 - Updated to latest SVN, fixing #705174 and #1007031 - Removed so versioning and fixed module loading, fixing #460557 and #1032547 -------------------------------------------------------------------------------- References: [ 1 ] Bug #705174 - echoping: boundary error in SSL-related functions can lead to buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=705174 [ 2 ] Bug #1007031 - echoping segfaults all the time https://bugzilla.redhat.com/show_bug.cgi?id=1007031 [ 3 ] Bug #460557 - echoping : Package and software are in a desolate state https://bugzilla.redhat.com/show_bug.cgi?id=460557 [ 4 ] Bug #1032547 - echoping doesn't seem to work (cannot open shared object file) https://bugzilla.redhat.com/show_bug.cgi?id=1032547 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update echoping' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPGkey. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
A buffer overflow in Echoping might allow remote attackers to cause a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201406-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Echoping: Buffer Overflow Vulnerabilities Date: June 06, 2014 Bugs: #349569 ID: 201406-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow in Echoping might allow remote attackers to cause a Denial of Service condition. Background ========= Echoping is a small program to test performances of a remote host by sending it TCP packets. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/echoping < 6.0.2_p434 > = 6.0.2_p434 Description ========== A boundary error exists within the "TLS_readline()" function, which can be exploited to overflow a global buffer by sending an overly long encrypted HTTP reply to Echoping. Also, a similar boundary error exists within the "SSL_readline()" function, which can be exploited in the same manner. Impact ===== A remote attacker could send a specially crafted HTTP reply, possibly resulting in a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Echoping users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =net-analyzer/echoping-6.0.2_p434" References ========= [ 1 ] CVE-2010-5111 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-5111 Availability =========== This GLSA and anyupdates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201406-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.