#1038975 sngrep: CVE-2023-36192

Package:
src:sngrep
Source:
src:sngrep
Submitter:
Salvatore Bonaccorso
Date:
2023-06-26 07:30:08 UTC
Severity:
normal
Tags:
#1038975#5
Date:
2023-06-23 20:50:28 UTC
From:
To:
Hi,

The following vulnerability was published for sngrep.

CVE-2023-36192[0]:
| Sngrep v1.6.0 was discovered to contain a heap buffer overflow via
| the function capture_ws_check_packet at /src/capture.c.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-36192
https://www.cve.org/CVERecord?id=CVE-2023-36192
[1] https://github.com/irontec/sngrep/issues/438
[2] https://github.com/irontec/sngrep/commit/ad1daf15c8387bfbb48097c25197bf330d2d98fc

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1038975#10
Date:
2023-06-26 07:23:54 UTC
From:
To:
Hi,

I've just uploaded to Sid sngrep 1.7.0-2 with [2] included.
I've prepared sngrep 1.6.0-2 for bookworm.

Waiting for you reply,
Victor

[0] https://security-tracker.debian.org/tracker/CVE-2023-36192
https://www.cve.org/CVERecord?id=CVE-2023-36192
[1] https://github.com/irontec/sngrep/issues/438
[2] https://github.com/irontec/sngrep/commit/ad1daf15c8387bfbb48097c25197bf330d2d98fc