Bug#334113: CAN-2005-3257 assigned

2005-10-18 Thread Martin Schulze
This one is CAN-2005-3257. Regards, Joey -- Never trust an operating system you don't have source for! Please always Cc to me when replying to me on the lists. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: debian-kernel archive

2005-10-18 Thread Bastian Blank
On Tue, Oct 18, 2005 at 02:23:01PM -0600, dann frazier wrote: > Seems like a reasonable thing to add to the kernel.alioth.debian.org > infrastructure (with an appropriate named dist), if you're interested - > unless you want to minimize public exposure of course. > http://lists.debian.org/debian-

Re: Bug#333858: Proposed improved patch for yaird

2005-10-18 Thread Sven Luther
On Tue, Oct 18, 2005 at 11:48:05PM +0200, Erik van Konijnenburg wrote: > On Tue, Oct 18, 2005 at 05:32:11PM +0200, Sven Luther wrote: > > On Tue, Oct 18, 2005 at 01:54:25PM +0200, Jonas Smedegaard wrote: > > > On Tue, 18 Oct 2005 11:51:43 +0200 Sven Luther <[EMAIL PROTECTED]> wrote: > > > > On Tue,

Bug#334113: [Secure-testing-team] Re: kernel allows loadkeys to be used by any user, allowing for local root compromise

2005-10-18 Thread Anthony DeRobertis
Krzysztof Halasa wrote: > Why doesn't the intruder just simulate login process (printing "login: " > and "Password:")? That's known and used for ages. Well, you can configure a single vty to only allow logins from admins. Then you avoid the fake login problem, but not the loadkeys problem (since

Bug#334631: FTBFS: Missing build-dependency on gcc-3.3

2005-10-18 Thread Matt Kraai
Package: kernel-source-2.4.27 Version: 2.4.27-11 Severity: serious Tags: patch kernel-source-2.4.27 fails to build: > gcc-3.3 -Wall -Wstrict-prototypes -O2 -fomit-frame-pointer -c -o docproc.o > docproc.c > make[5]: gcc-3.3: Command not found -- Matt diff -u kernel-source-2.4.27-2.4.27/debian/

Bug#333522: possible problem cause: wait4(-1)

2005-10-18 Thread Rusty Russell
On Tue, 2005-10-18 at 15:38 +0200, Martin Wilck wrote: > Rusty Russell wrote: > > > Martin Wilck <[EMAIL PROTECTED]> wrote: > > > >>0. the module loading tool runs during boot with PID 1. > > > > I do not understand how this can happen. request_module() cannot occur > > until usermodehelper_ini

Re: Re: Hyperthreading and debian kernels

2005-10-18 Thread Frederik Schueler
Hello, On Tue, Oct 18, 2005 at 11:02:54AM +0300, eng.Svilen Maximov wrote: > Problem occurs when I try 2.6.13.4: Only one CPU gets detected. Any idea what > the cause may be and how do I get it fixed? did you try linux-2.6-2.6.13 from experimental? can you post the .config and the dmesg showing

Re: Bug#333858: Proposed improved patch for yaird

2005-10-18 Thread Erik van Konijnenburg
On Tue, Oct 18, 2005 at 05:32:11PM +0200, Sven Luther wrote: > On Tue, Oct 18, 2005 at 01:54:25PM +0200, Jonas Smedegaard wrote: > > On Tue, 18 Oct 2005 11:51:43 +0200 Sven Luther <[EMAIL PROTECTED]> wrote: > > > On Tue, Oct 18, 2005 at 11:31:28AM +0200, Jonas Smedegaard wrote: > > > > > What do yo

Bug#334113: [Secure-testing-team] kernel allows loadkeys to be used by any user, allowing for local root compromise

2005-10-18 Thread Moritz Muehlenhoff
Horms wrote: > > The non-suid command "loadkeys" can be used by any local user having > > console access. It does not just apply to the current virtual console > > but to all virtual consoles and its effect persists even after logout. This has been assigned CAN-2005-3257. Cheers, Moritz

Bug#334113: kernel allows loadkeys to be used by any user, allowing for local root compromise

2005-10-18 Thread Rudolf Polzer
Scripsis, quam aut quem »Krzysztof Halasa« appellare soleo: > Rudolf Polzer <[EMAIL PROTECTED]> writes: > > That does not help against the loadkeys issue if the attacking user is still > > logged in on another virtual console. Even when tty1 is active, a user > > owning > > tty6 can use loadkeys.

Re: debian-kernel archive

2005-10-18 Thread dann frazier
On Tue, 2005-10-18 at 21:49 +0200, Bastian Blank wrote: > Hi folks > > I build a debian-kernel archive which will contain source and binary > snapshots of our kernel packages and neccesary packages to do cross > compilation. > > It is located on http://137.250.31.225/debian-kernel. > > Available

Re: yaird error message - HP DL360 Server / Kanotix 04 RC11

2005-10-18 Thread Erik van Konijnenburg
On Mon, Oct 17, 2005 at 03:46:30PM -0500, Marek Schneider wrote: > due to your mail I had today the possibility to run yaird as you > mentioned below. > Line 13 of /etc/fstab seems to be however different than it should be > --- > 12:# Added by KNOPPIX > 13: noauto,users,exec 0 0 > --- Th

debian-kernel archive

2005-10-18 Thread Bastian Blank
Hi folks I build a debian-kernel archive which will contain source and binary snapshots of our kernel packages and neccesary packages to do cross compilation. It is located on http://137.250.31.225/debian-kernel. Available distributions are for now sid and trunk, which matches the dists in the r

Processed: committed to svn

2005-10-18 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 258043 + pending Bug#258043: kernel-patch-debian-2.6.7: doesn't list which patches are incorporated: kernel-patch-debian-2.6.7, kernel-image-2.6.7: doesn't list which patches are incorporated There were no tags set. Tags added: pending > stop St

Bug#334113: kernel allows loadkeys to be used by any user, allowing for local root compromise

2005-10-18 Thread Krzysztof Halasa
Rudolf Polzer <[EMAIL PROTECTED]> writes: > That does not help against the loadkeys issue if the attacking user is still > logged in on another virtual console. Even when tty1 is active, a user owning > tty6 can use loadkeys. Sure. The problem is that mappings are shared between VCs but anyway it

Bug#334554: linux-image-2.6.12-1-686: unresolved symbols in snd_usb_audio kernel module

2005-10-18 Thread Maximilian Attems
On Tue, Oct 18, 2005 at 12:58:18PM -0400, Keith Geffert wrote: > Loading snd_usb_audio fails with unresolved symbols. I use a Logitech > USB Mic frequently and after the 2.6.12 upgrade hotplug now fails to > load the alsa device module. 2.6.10-x-686 does not exhibit this > behavior. > > Sample sy

Bug#334113: kernel allows loadkeys to be used by any user, allowing for local root compromise

2005-10-18 Thread Rudolf Polzer
Scripsis, quam aut quem »Krzysztof Halasa« appellare soleo: > Horms <[EMAIL PROTECTED]> writes: > > >> Then log out and let root login (in a computer pool, you can usually get > >> an admin to log on as root on a console somehow). The next time he'll > >> press TAB to complete a file name, he inst

Bug#334554: linux-image-2.6.12-1-686: unresolved symbols in snd_usb_audio kernel module

2005-10-18 Thread Keith Geffert
Package: linux-image-2.6.12-1-686 Version: 2.6.12-10 Severity: normal Loading snd_usb_audio fails with unresolved symbols. I use a Logitech USB Mic frequently and after the 2.6.12 upgrade hotplug now fails to load the alsa device module. 2.6.10-x-686 does not exhibit this behavior. Sample syslog

Bug#334548: kernel error: invalid operand: 0000

2005-10-18 Thread Leandro Piccilli
package: linux-image-2.6.13-1-686 X and others programs are crashing constantly in my machine. I cannot reproduce exactly. Sometimes i got these errors on dmesg: invalid operand: [#1] Modules linked in: binfmt_misc ipt_state ipt_LOG ipt_limit iptable_filter ip_nat_ftp ip_conntrack_ftp ip

Re: Bug#333858: Proposed improved patch for yaird

2005-10-18 Thread Sven Luther
On Tue, Oct 18, 2005 at 01:54:25PM +0200, Jonas Smedegaard wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On Tue, 18 Oct 2005 11:51:43 +0200 > Sven Luther <[EMAIL PROTECTED]> wrote: > > > On Tue, Oct 18, 2005 at 11:31:28AM +0200, Jonas Smedegaard wrote: > > > -BEGIN PGP SIGNED M

Bug#334113: kernel allows loadkeys to be used by any user, allowing for local root compromise

2005-10-18 Thread Krzysztof Halasa
Horms <[EMAIL PROTECTED]> writes: >> Then log out and let root login (in a computer pool, you can usually get >> an admin to log on as root on a console somehow). The next time he'll >> press TAB to complete a file name, he instead will run the shell >> command. Why doesn't the intruder just simu

Re: Re: Pentium III laptop _instant_ shutdown during custom kernel compile!

2005-10-18 Thread Harald Bauer
your box could be overheating while compiling, if it was the case acpi has to shutdown your box. I had the same Problem. The boot option acpi=on I solved the problem -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#333522: possible problem cause: wait4(-1)

2005-10-18 Thread Martin Wilck
Rusty Russell wrote: Martin Wilck <[EMAIL PROTECTED]> wrote: 0. the module loading tool runs during boot with PID 1. I do not understand how this can happen. request_module() cannot occur until usermodehelper_init() is called. This is only done once the init thread is spawned, which should

Re: Bug#333858: Proposed improved patch for yaird

2005-10-18 Thread Jonas Smedegaard
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tue, 18 Oct 2005 11:51:43 +0200 Sven Luther <[EMAIL PROTECTED]> wrote: > On Tue, Oct 18, 2005 at 11:31:28AM +0200, Jonas Smedegaard wrote: > > -BEGIN PGP SIGNED MESSAGE- > > > What do you think? > > > > Well, after some thinking I actually

Re: Bug#333858: Proposed improved patch for yaird

2005-10-18 Thread Sven Luther
On Tue, Oct 18, 2005 at 11:31:28AM +0200, Jonas Smedegaard wrote: > -BEGIN PGP SIGNED MESSAGE- > > What do you think? > > Well, after some thinking I actually think we would actually be better > off with both core and debian dir at Alioth but separate from > debian-kernel. Well, you do wh

Processed: Re: Bug#334348: kernel-kbuild-2.6-3: Warning for mismatched gcc versions suggested

2005-10-18 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tag 334348 -patch Bug#334348: kernel-kbuild-2.6-3: Warning for mismatched gcc versions suggested Tags were: wontfix patch Tags removed: patch > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system admi

Bug#334348: kernel-kbuild-2.6-3: Warning for mismatched gcc versions suggested

2005-10-18 Thread Horms
tag 334348 -patch thanks On Tue, Oct 18, 2005 at 11:10:05AM +0200, Eduard Bloch wrote: > #include > * Marv Stodolsky [Mon, Oct 17 2005, 02:13:40PM]: > > Package: kernel-kbuild-2.6-3 > > Version: 2.6.8-2 > > Severity: wishlist > > Tags: patch > > Where is your patch? I see just an obscure wish.

Re: Bug#333858: Proposed improved patch for yaird

2005-10-18 Thread Jonas Smedegaard
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tue, 18 Oct 2005 07:54:38 +0200 Erik van Konijnenburg <[EMAIL PROTECTED]> wrote: > On Mon, Oct 17, 2005 at 09:57:49AM +0200, Jonas Smedegaard wrote: > > On Sun, 16 Oct 2005 23:57:59 +0200 Sven Luther > > <[EMAIL PROTECTED]> wrote: > > > On Sun, Oct

Bug#334467: /bin/sh: error while loading shared libraries: libm.so.6

2005-10-18 Thread Maximilian Attems
On Tue, Oct 18, 2005 at 10:37:03AM +0200, Maximilian Attems wrote: > tags 334467 pending > stop > > On Tue, Oct 18, 2005 at 08:05:06AM +0200, Jean Charles Delépine wrote: > > poucet:/home/jcd# mkinitramfs -k -o /boot/initramfs.img-2.6.14-rc4-git4 > > 2.6.14-rc4-git4 > > Working files in /tmp/mkini

Bug#334348: kernel-kbuild-2.6-3: Warning for mismatched gcc versions suggested

2005-10-18 Thread Sven Luther
On Tue, Oct 18, 2005 at 11:10:05AM +0200, Eduard Bloch wrote: > #include > * Marv Stodolsky [Mon, Oct 17 2005, 02:13:40PM]: > > Package: kernel-kbuild-2.6-3 > > Version: 2.6.8-2 > > Severity: wishlist > > Tags: patch > > Where is your patch? I see just an obscure wish. > > Hint: packages using m

Bug#334348: kernel-kbuild-2.6-3: Warning for mismatched gcc versions suggested

2005-10-18 Thread Eduard Bloch
#include * Marv Stodolsky [Mon, Oct 17 2005, 02:13:40PM]: > Package: kernel-kbuild-2.6-3 > Version: 2.6.8-2 > Severity: wishlist > Tags: patch Where is your patch? I see just an obscure wish. Hint: packages using module-assistant do already choose the right compiler or print a warning like the o

Bug#334113: [Security] kernel allows loadkeys to be used by any user, allowing for local root compromise

2005-10-18 Thread Horms
On Mon, Oct 17, 2005 at 11:52:11PM -0700, Andrew Morton wrote: > Horms <[EMAIL PROTECTED]> wrote: > > > > drivers/char/vt_ioctl.c: vt_ioctl(): line 377 > > > > /* > > * To have permissions to do most of the vt ioctls, we either > > * have > > * to be the owne

Processed: Re: Bug#334467: /bin/sh: error while loading shared libraries: libm.so.6

2005-10-18 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 334467 pending Bug#334467: /bin/sh: error while loading shared libraries: libm.so.6 There were no tags set. Tags added: pending > stop Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (

Bug#334467: /bin/sh: error while loading shared libraries: libm.so.6

2005-10-18 Thread Maximilian Attems
tags 334467 pending stop On Tue, Oct 18, 2005 at 08:05:06AM +0200, Jean Charles Delépine wrote: > poucet:/home/jcd# mkinitramfs -k -o /boot/initramfs.img-2.6.14-rc4-git4 > 2.6.14-rc4-git4 > Working files in /tmp/mkinitramfs_R9QJFq and overlay in > /tmp/mkinitramfs-OL_mPaz0q > poucet:/home/jcd# cp

Bug#334275: marked as done (linux-image-2.6.13-1-686: ide error messages come up)

2005-10-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Oct 2005 08:33:50 +0200 with message-id <[EMAIL PROTECTED]> and subject line Bug#334275: linux-image-2.6.13-1-686: ide error messages come up has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this

Bug#334273: marked as done (linux-image-2.6.13-1-686: /etc/init.d/dbus-1 causes kernel oops)

2005-10-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Oct 2005 08:21:05 +0200 with message-id <[EMAIL PROTECTED]> and subject line Bug#334273: linux-image-2.6.13-1-686: /etc/init.d/dbus-1 causes kernel oops has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt wi

Bug#334113: [Security] kernel allows loadkeys to be used by any user, allowing for local root compromise

2005-10-18 Thread Andrew Morton
Horms <[EMAIL PROTECTED]> wrote: > > drivers/char/vt_ioctl.c: vt_ioctl(): line 377 > > /* > * To have permissions to do most of the vt ioctls, we either > * have > * to be the owner of the tty, or have CAP_SYS_TTY_CONFIG. > */ > perm = 0; >

Bug#334104: tulip driver advertises support for non-working card

2005-10-18 Thread Marco d'Itri
On Oct 18, Jurij Smakov <[EMAIL PROTECTED]> wrote: > The original report states that downgrading udev and using it with the > *same* kernel fixes the situation. How can it be a kernel bug? If a driver advertises to support some hardware but then does not work it's a kernel bug. The latest udev ma

Bug#333842: linux-headers-2.6.12-1-686: .extraversion only has - rather than -1-686

2005-10-18 Thread Horms
On Fri, Oct 14, 2005 at 10:38:49AM +, [EMAIL PROTECTED] wrote: > RE:Could you please go back to the page you were looking > and report the bug numbers, they are preceeded by a #. > > Don't have time this AM, but will respond to > > RE: Could you give some details of the failure that y

Re: Re: Hyperthreading and debian kernels

2005-10-18 Thread eng.Svilen Maximov
Hi,   I seem to have another problem with the hyperthreading of P4:   Day1-Global:~# cat /proc/cpuinfoprocessor   : 0vendor_id   : GenuineIntelcpu family  : 15model   : 4model name  : Intel(R) Pentium(R) 4 CPU 3.00GHzstepping    : 3cpu MHz : 3157.323ca

Bug#334467: /bin/sh: error while loading shared libraries: libm.so.6

2005-10-18 Thread Jean Charles Delépine
Package: initramfs-tools Version: 0.31 Severity: critical Justification: breaks the whole system Hello, poucet:/home/jcd# mkinitramfs -k -o /boot/initramfs.img-2.6.14-rc4-git4 2.6.14-rc4-git4 Working files in /tmp/mkinitramfs_R9QJFq and overlay in /tmp/mkinitramfs-OL_mPaz0q poucet:/home/jcd# cp

Bug#334113: kernel allows loadkeys to be used by any user, allowing for local root compromise

2005-10-18 Thread Horms
On Sat, Oct 15, 2005 at 06:03:31PM +0200, Rudolf Polzer wrote: > Package: linux-image-2.6.12-1-powerpc > Version: 2.6.12-10 > Severity: critical > Tags: security > Justification: root security hole > > > The non-suid command "loadkeys" can be used by any local user having > console access. It doe

Bug#334113: linux-image-2.6.12-1-powerpc: kernel allows loadkeys to be used by any user, allowing for local root compromise

2005-10-18 Thread Horms
Thanks, that seems like a genuine problem, I am forwarding it upstream for consideration as it is not immediately apparent to me what the best solution is. -- Horms -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#332559: kernel-image-2.6.8-2-686: Serial not working

2005-10-18 Thread Jonas Bevren
Horms, Thanks for the attention. Your note mentions a kernel that doesnt exist (2.6.26-5.99.sarge1). however, I made a guess at your intent being the 2.6.12-5.99 kernel, and tested it. I recorded a session log from the system. It has a bios-managed serial console, so an ansi viewer would be o

Re: Bug#333858: Proposed improved patch for yaird

2005-10-18 Thread Sven Luther
On Tue, Oct 18, 2005 at 07:54:38AM +0200, Erik van Konijnenburg wrote: > On Mon, Oct 17, 2005 at 09:57:49AM +0200, Jonas Smedegaard wrote: > > On Sun, 16 Oct 2005 23:57:59 +0200 Sven Luther <[EMAIL PROTECTED]> wrote: > > > On Sun, Oct 16, 2005 at 10:35:45PM +0200, Jonas Smedegaard wrote: > > > > Bu