Re: Bug#564079: Is this really a screensaver issue?

2010-01-26 Thread Nico Golde
the system e.g. via an own account. > > I???d appreciate if we could have some input from the kernel maintainers. > > Someone with access to the console have several attack vectors > available. True, but this one is trivial to exploit and is also fairly easy to prevent so why s

Bug#550534: firmware-iwlwifi: iwlagn 0000:03:00.0: Microcode SW error detected. Restarting 0x82000000

2009-11-12 Thread Nico Golde
severity 550534 grave thanks Hi, I have similar issues using Intel Corporation PRO/Wireless 4965 AG or AGN [Kedron] Network Connection (rev 61). >From dmesg: [ 105.305807] iwlagn :03:00.0: firmware: requesting iwlwifi-4965-2.ucode [ 105.390624] iwlagn :03:00.0: loaded firmware version

Bug#529326: linux-2.6: CVE-2009-0787 information disclosure in ecryptfs

2009-05-18 Thread Nico Golde
t; the headers even though the size of the headers maybe > the page size. Yes and you are correct with this, no other version included the vulnerable code. Cheers Nico -- Nico Golde - http://www.ngolde.de - n...@jabber.ccc.de - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpiFLvSwMX01.pgp Description: PGP signature

Bug#496410: The possibility of attack with the help of symlinks in some Debian packages

2008-10-17 Thread Nico Golde
http://security-tracker.debian.net/tracker/CVE-2008-4579 [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4580 http://security-tracker.debian.net/tracker/CVE-2008-4580 Cheers Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in

Bug#490910: linux-2.6: CVE-2008-0598 information disclosure

2008-07-15 Thread Nico Golde
.cgi?id=311794 The path to this file changed, it's x86/lib/copy_user_64.S in our source packages. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0598 http://security-tracker.debian.net/tracker/CVE-2008-0598 -- Nico Golde - http://www.ngolde.de

Bug#485944: retitle 485944 to linux-2.6: CVE-2008-1673 problem when validating length values during decoding of ASN.1 BER data

2008-06-12 Thread Nico Golde
# Automatically generated email from bts, devscripts version 2.10.29 # args retitled wrong bug retitle 485944 linux-2.6: CVE-2008-1673 problem when validating length values during decoding of ASN.1 BER data -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble

Bug#485944: linux-2.6: CVE-2008-1673 problem when validating length values during decoding of ASN.1 BER data

2008-06-12 Thread Nico Golde
also make sure to include the CVE id in your changelog entry. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1673 http://security-tracker.debian.net/tracker/CVE-2008-1673 -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For secu

Bug#481195: linux-2.6: CVE-2008-2148 local denial of service

2008-05-14 Thread Nico Golde
/CVE-2008-2148 -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgp05JUQyrSDx.pgp Description: PGP signature

Bug#480390: linux-2.6: CVE-2008-1615 local denial of service on amd64

2008-05-09 Thread Nico Golde
Hi Bastian, * Bastian Blank <[EMAIL PROTECTED]> [2008-05-09 19:54]: > fixed 480390 2.6.25-1 > thanks > > On Fri, May 09, 2008 at 07:10:54PM +0200, Nico Golde wrote: > > the following CVE (Common Vulnerabilities & Exposures) id was > > published for linux-2.6.

Bug#480390: linux-2.6: CVE-2008-1615 local denial of service on amd64

2008-05-09 Thread Nico Golde
further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1615 http://security-tracker.debian.net/tracker/CVE-2008-1615 -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 en

Bug#474966: ACPI seems to have changed interface

2008-04-08 Thread Nico Golde
had changed in 2.6.24 the acpi stuff for battery moved to the sysfs interface. So this is no kernel bug but a bug in xfce4-battery-plugins that also affect a bunch of acpi tools in Debian. Reading http://www.corsac.net/?rub=blog&post=1400 this should work in xfce4-battery-plugin 0.5.0-6. C

Bug#446073: CVE-2007-3843 possible spoofing of CIFS traffic

2007-10-10 Thread Nico Golde
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3843 Kind regards Nico -- Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpn3YECGy5xd.pgp Description: PGP signature

Bug#444571: CVE-2007-4571 sensitive information disclosure

2007-09-29 Thread Nico Golde
d in your changelog entry. You can find a fix on: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ccec6e2c4a74adf76ed4e2478091a311b1806212 For further information: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4571 Kind regards Nico -- Nico Golde -

Bug#443694: CVE-2007-4308 missing permissions check for ioctls in aacraid

2007-09-23 Thread Nico Golde
.cgi?name=CVE-2007-4308 Kind regards Nico -- Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpM0xqkgkCOK.pgp Description: PGP signature

Bug#442245: CVE-2007-4849 insecure permission storage in JFFS2

2007-09-14 Thread Nico Golde
se include the CVE id in the changelog. [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4849 Kind regards Nico -- Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpl6CgpfxSYD.pgp Descri

Bug#356387: ipw2100 does not work anylonger

2006-03-11 Thread Nico Golde
-1-686: true linux-image-2.6.15-1-686/preinst/failed-to-move-modules-2.6.15-1-686: linux-image-2.6.15-1-686/preinst/elilo-initrd-2.6.15-1-686: true linux-image-2.6.15-1-686/postinst/old-system-map-link-2.6.15-1-686: true -- Nico Golde - JAB: [EMAIL PROTECTED] | GPG: 0x73647CFF http://

Re: config.gz files

2005-05-06 Thread Nico Golde
Hello Matus, * Matus UHLAR - fantomas <[EMAIL PROTECTED]> [2005-05-06 17:45]: > On 06.05 10:42, Nico Golde wrote: > > why the debian kernel-packages don't provide the config file > > via /proc? > > For 2.4 kernels, it requires patch that is not in debian distribu

config.gz files

2005-05-06 Thread Nico Golde
Hi, why the debian kernel-packages don't provide the config file via /proc? Please CC me, I am not on this list. Regards Nico -- Nico Golde - [EMAIL PROTECTED] | GPG: 1024D/73647CFF http://www.ngolde.de | http://www.muttng.org | http://grml.org VIM has two modes - the one in which it beeps