Bug#792490: openssl s_client doesn't allow for certificate pinning anymore!

2015-07-15 Thread Florent Daigniere
Package: openssl Version: 1.0.2d-1 Severity: grave Tags: security Justification: user security hole Dear Maintainer, It looks like openssl s_client is not providing any way to disregard the system's trusted CAs anymore... and this is a regression from Jessie. with 1.0.2d-1 (sid) $strace -f -e o

Bug#574935: iscsitarget: Format string vulnerability

2010-03-22 Thread Florent Daigniere
Package: iscsitarget Version: 0.4.16+svn162-3 Severity: critical Tags: security Justification: root security hole There is at least two remotely exploitable format string vulnerabilities in the debian stable package... which have been fixed upstream. isns.c:302 isns.c:690 The default init scri