Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-25 Thread Adam D. Barratt
On Fri, 2013-05-24 at 23:05 +0200, Florian Weimer wrote: > * Adam D. Barratt: > > > On Fri, 2013-05-24 at 22:20 +0200, Florian Weimer wrote: > >> * Steven Chamberlain: > >> > I notice a problem though when this was (I think - I'm unsure of the > >> > security team's processes here) copied to the m

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-24 Thread Florian Weimer
* Adam D. Barratt: > On Fri, 2013-05-24 at 22:20 +0200, Florian Weimer wrote: >> * Steven Chamberlain: >> > I notice a problem though when this was (I think - I'm unsure of the >> > security team's processes here) copied to the main archive, probably so >> > that it can be included in stable-propo

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-24 Thread Adam D. Barratt
On Fri, 2013-05-24 at 22:20 +0200, Florian Weimer wrote: > * Steven Chamberlain: > > I notice a problem though when this was (I think - I'm unsure of the > > security team's processes here) copied to the main archive, probably so > > that it can be included in stable-proposed-updates: > > Thanks f

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-24 Thread Florian Weimer
* Steven Chamberlain: > Hi, > > On 22/05/13 19:46, Florian Weimer wrote: >> Sorry for the delay. I'm taking care of this now. > > Thank you for the DSA. > > I notice a problem though when this was (I think - I'm unsure of the > security team's processes here) copied to the main archive, probably

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-24 Thread Steven Chamberlain
Hi, On 22/05/13 19:46, Florian Weimer wrote: > Sorry for the delay. I'm taking care of this now. Thank you for the DSA. I notice a problem though when this was (I think - I'm unsure of the security team's processes here) copied to the main archive, probably so that it can be included in stable-

Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-22 Thread Florian Weimer
* Steven Chamberlain: > On 01/05/13 15:20, Christoph Egger wrote: >> Florian Weimer writes: >>> Looks good. Please upload to security-master directly. You have to >>> rebuild with -sa, though, so that the upstream tarball is included in >>> the upload. >> >> Should be somewhere in your queue n

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-21 Thread Steven Chamberlain
Dear Security Team, On 01/05/13 15:20, Christoph Egger wrote: > Florian Weimer writes: >> Looks good. Please upload to security-master directly. You have to >> rebuild with -sa, though, so that the upstream tarball is included in >> the upload. > > Should be somewhere in your queue now Was th

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-01 Thread Christoph Egger
Florian Weimer writes: > * Christoph Egger: > >> Packages will be in people.d.o:~christoph soon (or shall I upload to >> security directly? > > Looks good. Please upload to security-master directly. You have to > rebuild with -sa, though, so that the upstream tarball is included in > the upload.

Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-01 Thread Christoph Egger
Hi! Steven Chamberlain writes: > Is that the correct version number for a security upload? (9.0-10+deb70.1) > > I'm more used to seeing something like +wheezy1 As +wheezy actually is larger that +jessie the +deb$something are the new style for stable version numbering as far as I understand

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-01 Thread Steven Chamberlain
Is that the correct version number for a security upload? (9.0-10+deb70.1) I'm more used to seeing something like +wheezy1 Regards, -- Steven Chamberlain ste...@pyro.eu.org -- To UNSUBSCRIBE, email to debian-bsd-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listma

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-01 Thread Florian Weimer
* Christoph Egger: > Packages will be in people.d.o:~christoph soon (or shall I upload to > security directly? Looks good. Please upload to security-master directly. You have to rebuild with -sa, though, so that the upstream tarball is included in the upload. -- To UNSUBSCRIBE, email to debi

Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-01 Thread Christoph Egger
Florian Weimer writes: > * Christoph Egger: > >> Hi! >> >> Steven Chamberlain writes: >>> tags 706414 + pending >>> thanks >>> >>> I've applied upstream's patch in SVN, I'm running it now on my NFS >>> server and seems okay. >>> >>> Christoph, would you be able to do an upload of this to unstable

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-01 Thread Florian Weimer
* Christoph Egger: > Hi! > > Steven Chamberlain writes: >> tags 706414 + pending >> thanks >> >> I've applied upstream's patch in SVN, I'm running it now on my NFS >> server and seems okay. >> >> Christoph, would you be able to do an upload of this to unstable please? > > I'm building right now.

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-01 Thread Steven Chamberlain
On 01/05/13 11:14, Christoph Egger wrote: > [...] As it is too late for wheezy r0 it seems we'll > need to go through either security or stable-updates for wheezy Yes, we need to fix it in sid anyway. I think this (in kfreebsd-9) merits a DSA and the fix made available via security.d.o as soon as

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-05-01 Thread Christoph Egger
Hi! Steven Chamberlain writes: > tags 706414 + pending > thanks > > I've applied upstream's patch in SVN, I'm running it now on my NFS > server and seems okay. > > Christoph, would you be able to do an upload of this to unstable please? I'm building right now. As it is too late for wheezy r0 it

Processed: Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-04-30 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > user release.debian@packages.debian.org Setting user to release.debian@packages.debian.org (was a...@adam-barratt.org.uk). > usertags 706414 + wheezy-can-defer There were no usertags set. Usertags are now: wheezy-can-defer. > tags 706414

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-04-30 Thread Adam D. Barratt
user release.debian@packages.debian.org usertags 706414 + wheezy-can-defer tags 706414 + wheezy-ignore thanks On Mon, 2013-04-29 at 23:53 +0100, Steven Chamberlain wrote: > I've applied upstream's patch in SVN, I'm running it now on my NFS > server and seems okay. > > Christoph, would you be

Processed: Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-04-29 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 706414 + pending Bug #706414 [src:kfreebsd-9] CVE-2013-3266: Insufficient input validation in the NFS server Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 706414: http://bugs.debian.o

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-04-29 Thread Steven Chamberlain
tags 706414 + pending thanks I've applied upstream's patch in SVN, I'm running it now on my NFS server and seems okay. Christoph, would you be able to do an upload of this to unstable please? Many thanks, Regards, -- Steven Chamberlain ste...@pyro.eu.org -- To UNSUBSCRIBE, email to debian-bs

Processed (with 3 errors): Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-04-29 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > clone 706414 -1 Bug #706414 [src:kfreebsd-9] CVE-2013-3266: Insufficient input validation in the NFS server Bug 706414 cloned as bug 706418 > reassign -1 src:kfreebsd-8 Bug #706418 [src:kfreebsd-9] CVE-2013-3266: Insufficient input validation in

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-04-29 Thread Steven Chamberlain
clone 706414 -1 reassign -1 src:kfreebsd-8 found -1 8.3-6 severity -1 important This bug also affects kfreebsd-8, but the vulnerable NFS implementation is not the one used by default in 8.x kernels. Regards, -- Steven Chamberlain ste...@pyro.eu.org -- To UNSUBSCRIBE, email to debian-bsd-requ.

Re: Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-04-29 Thread Steven Chamberlain
On 29/04/13 22:46, Steven Chamberlain wrote: > Upstream published a security advisory for the nfsserver implementation > as shipped by kfreebsd-9 packages. (See above URL for reference). Correction for security advisory URL: http://security.freebsd.org/advisories/FreeBSD-SA-13:05.nfsserver.asc R

Bug#706414: CVE-2013-3266: Insufficient input validation in the NFS server

2013-04-29 Thread Steven Chamberlain
Source: kfreebsd-9 Version: 9.0-10 Severity: grave Tags: security upstream Forwarded: http://security.freebsd.org/patches/SA-03:05/nfsserver.patch Upstream published a security advisory for the nfsserver implementation as shipped by kfreebsd-9 packages. (See above URL for reference). Insufficien