Bug#645377: kfreebsd-8: Buffer overflow in handling of UNIX socket addresses

2011-10-14 Thread Michael Gilbert
package: kfreebsd-8 version: 8.1 severity: serious tag: security , patch A buffer overflow issue in kfreebsd has been disclosed [0] along with a poc [1]. patch is available [2]. I've only checked the kfreebsd-8 source, but the description says -7 is affected, and 9- and higher may be as well; I h

Re: Please test zfsutils 9.0~svn226163-1

2011-10-14 Thread Guillem Jover
On Mon, 2011-10-10 at 01:35:36 +0200, Arno Töll wrote: > * We could get rid of the last delta in 01_glibc_kludge.diff and the > whole (hacky and ugly) 16-wrap-cdefs.diff if kfreebsd-kernel-headers > would export cdefs.h like it does upstream [2]. As Petr has said is already exported by eglibc, th

Re: Please test zfsutils 9.0~svn226163-1

2011-10-14 Thread Guillem Jover
Hi! On Mon, 2011-10-10 at 11:43:22 +0200, Arno Töll wrote: > On 10.10.2011 07:06, Robert Millan wrote: > > This wouldn't be accepted in Debian archive. There's an RFP for this > > library, but it needs some cleanup in debian/copyright before it can > > be uploaded IIRC. > > Note we do this alrea

Re: [pkg-wpa-devel] Bug#644823: uninstallable on kfreebsd-* (depends on uninstallable libpcap0.8 from non-udeb land)

2011-10-14 Thread Robert Millan
2011/10/14 Stefan Lippers-Hollmann : > It would be great if you could sponsor that upload, as I can only try > to contact our regular sponsor this evening. Done. >> In the meantime we could file a wishlist request to libpcap >> maintainer?  I don't have time to prepare a patch but maybe he's >> w

Re: Please test zfsutils 9.0~svn226163-1

2011-10-14 Thread Arno Töll
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 14.10.2011 07:21, Robert Millan wrote: > I'm sure, but note 8-STABLE != 8.2.0-RELEASE. I'm talking about the > stable/8 branch, which will become 8.3.0-RELEASE. whoops, sorry for the confusion then. > It'd be interesting to know if 8-STABLE versi

Bug#645305: zfsutils dependencies break ABI and aren't properly versioned

2011-10-14 Thread Arno Töll
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Package: src:zfsutils Version: 8.1-4+squeeze1 Severity: serious Justification: breaks upgrades, does not declare dependencies properly Out of the zfsutils package are being built several shared libraries. These do not bump any SONAME version or provi

Re: [pkg-wpa-devel] Bug#644823: uninstallable on kfreebsd-* (depends on uninstallable libpcap0.8 from non-udeb land)

2011-10-14 Thread Stefan Lippers-Hollmann
Hi On Friday 14 October 2011, Robert Millan wrote: > Hi Stefan, > > 2011/10/13 Stefan Lippers-Hollmann : > > Does this affect daily d-i builds or is it 'just' wpasupplicant-udeb > > (new package) being unusable without affecting the kfreebsd ports yet? > > It breaks daily builds. > > > So as fa