Re: [Secure-testing-team] Re: Bug#322273: [CAN-2005-2456]: XFRM array index buffer overflow

2005-08-10 Thread Horms
On Wed, Aug 10, 2005 at 11:47:12AM +0200, Moritz Muehlenhoff wrote: > Horms wrote: > > As for which package to log a bug against, or cretion of duplicate bugs. > > To be honest it doesn't matter. If you email > > debian-kernel@lists.debian.org, then you should get a response, > > regardless of if y

CAN-2005-2500 (Was: Re: Bug#322273: [CAN-2005-2456]: XFRM array index buffer overflow)

2005-08-10 Thread Horms
On Wed, Aug 10, 2005 at 12:04:05PM +0200, Christoph Hellwig wrote: > On Wed, Aug 10, 2005 at 11:47:12AM +0200, Moritz Muehlenhoff wrote: > > Horms wrote: > > > As for which package to log a bug against, or cretion of duplicate bugs. > > > To be honest it doesn't matter. If you email > > > debian-ke

Re: [Secure-testing-team] Re: Bug#322273: [CAN-2005-2456]: XFRM array index buffer overflow

2005-08-10 Thread Christoph Hellwig
On Wed, Aug 10, 2005 at 11:47:12AM +0200, Moritz Muehlenhoff wrote: > Horms wrote: > > As for which package to log a bug against, or cretion of duplicate bugs. > > To be honest it doesn't matter. If you email > > debian-kernel@lists.debian.org, then you should get a response, > > regardless of if y

Re: [Secure-testing-team] Re: Bug#322273: [CAN-2005-2456]: XFRM array index buffer overflow

2005-08-10 Thread Moritz Muehlenhoff
Horms wrote: > As for which package to log a bug against, or cretion of duplicate bugs. > To be honest it doesn't matter. If you email > debian-kernel@lists.debian.org, then you should get a response, > regardless of if you open a bug in the BTS or not. > CCing secure-testing-team@lists.alioth.debi

Bug#322273: [CAN-2005-2456]: XFRM array index buffer overflow

2005-08-09 Thread Horms
tag kernel-source-2.6.8 +pending thanks On Wed, Aug 10, 2005 at 02:53:07PM +1000, Geoff Crompton wrote: > Package: kernel-source-2.6.8 > Version: 2.6.8-16 > Severity: critical > Justification: root security hole > > SecurityFocus http://www.securityfocus.com/bid/14477 mentions an array index > b

Bug#322273: [CAN-2005-2456]: XFRM array index buffer overflow

2005-08-09 Thread Geoff Crompton
Package: kernel-source-2.6.8 Version: 2.6.8-16 Severity: critical Justification: root security hole SecurityFocus http://www.securityfocus.com/bid/14477 mentions an array index buffer overflow. In short, the suspect it can cause a denial of service attack, but aren't sure whether or not it allows