• Bug#1105806: net-tools: diff for NMU version 2.10-1.2

    From Salvatore Bonaccorso@21:1/5 to All on Thu May 15 06:00:01 2025
    Control: tags 1105806 + patch
    Control: tags 1105806 + pending


    Dear maintainer,

    I've prepared an NMU for net-tools (versioned as 2.10-1.2) and
    uploaded it to DELAYED/2. Please feel free to tell me if I
    should cancel it.

    Aiming to get the change in trixie ideally, thus already proposing the
    NMU, and uploading to delayed.

    Regards,
    Salvatore

    diffstat for net-tools-2.10 net-tools-2.10

    changelog | 8
    patches/CVE-2025-46836-interface.c-Stack-based-Buffer-Overfl.patch | 92 ++++++++++
    patches/series | 1
    3 files changed, 101 insertions(+)

    diff -Nru net-tools-2.10/debian/changelog net-tools-2.10/debian/changelog
    --- net-tools-2.10/debian/changelog 2024-04-22 01:55:29.000000000 +0200
    +++ net-tools-2.10/debian/changelog 2025-05-15 05:43:50.000000000 +0200
    @@ -1,3 +1,11 @@
    +net-tools (2.10-1.2) unstable; urgency=medium
    +
    + * Non-maintainer upload.
    + * CVE-2025-46836: interface.c: Stack-based Buffer Overflow in get_name()
    + (Closes: #1105806)
    +
    + -- Salvatore Bonaccorso <carnil@debian.org> Thu, 15 May 2025 05:43:50 +0200 +
    net-tools (2.10-1.1) unstable; urgency=medium

    * Non-maintainer upload.
    diff -Nru net-tools-2.10/debian/patches/CVE-2025-46836-interface.c-Stack-based-Buffer-Overfl.patch net-tools-2.10/debian/patches/CVE-2025-46836-interface.c-Stack-based-Buffer-Overfl.patch
    --- net-tools-2.10/debian/patches/CVE-2025-46836-interface.c-Stack-based-Buffer-Overfl.patch 1970-01-01 01:00:00.000000000 +0100
    +++ net-tools-2.10/debian/patches/CVE-2025-46836-interface.c-Stack-based-Buffer-Overfl.patch 2025-05-15 05:43:50.000000000 +0200
    @@ -0,0 +1,92 @@
    +From: Zephkeks <zephyrofficialdiscord@gmail.c
  • From Salvatore Bonaccorso@21:1/5 to Salvatore Bonaccorso on Thu May 15 15:50:01 2025
    Hi,

    On Thu, May 15, 2025 at 05:50:11AM +0200, Salvatore Bonaccorso wrote:
    Control: tags 1105806 + patch
    Control: tags 1105806 + pending


    Dear maintainer,

    I've prepared an NMU for net-tools (versioned as 2.10-1.2) and
    uploaded it to DELAYED/2. Please feel free to tell me if I
    should cancel it.

    Aiming to get the change in trixie ideally, thus already proposing the
    NMU, and uploading to delayed.

    FTR, Martina acknowledged offlist to move the upload directy, so have
    just rescheduled it, thank you!

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)