Re: Bug#552433: stable update: nss-ldapd (#552433: libnss-ldapd: ignores case of uids)

2009-12-16 Thread Arthur de Jong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sun, 2009-12-06 at 17:48 +0100, Arthur de Jong wrote: I have prepared a 0.6.7.2 version which can be found here: [2], [3]. The debdiff is attached (9 source files changed, 133 insertions and 151 deletions). Please go ahead. Thanks, I will up

Re: stable update: nss-ldapd (#552433: libnss-ldapd: ignores case of uids)

2009-12-13 Thread Adam D. Barratt
On Sun, 2009-12-06 at 17:48 +0100, Arthur de Jong wrote: > I have prepared a 0.6.7.2 version which can be found here: [2], [3]. The > debdiff is attached (9 source files changed, 133 insertions and 151 > deletions). Please go ahead. Regards, Adam -- To UNSUBSCRIBE, email to debian-release-requ

Re: Bug#552433: stable update: nss-ldapd (#552433: libnss-ldapd: ignores case of uids)

2009-12-13 Thread Petter Reinholdtsen
[Arthur de Jong] > I it OK to upload this to proposed-updates? Did you get any feedback on this? This issue is one of the blocking issues for the next Debian Edu release, and thus it would be nice to know the timeline for a fix in Lenny. :) Happy hacking, -- Petter Reinholdtsen -- To UNSUBSC

Re: stable update: nss-ldapd (#552433: libnss-ldapd: ignores case of uids)

2009-12-07 Thread Holger Levsen
Hi, On Sonntag, 6. Dezember 2009, Arthur de Jong wrote: > I brought up bug #552433 here earlier [0] and have been in contact with > the security team about this but haven't had a definite answer from them > whether they want (or don't want) to issue an advisory for this. > > I'm now convinced this

stable update: nss-ldapd (#552433: libnss-ldapd: ignores case of uids)

2009-12-06 Thread Arthur de Jong
I brought up bug #552433 here earlier [0] and have been in contact with the security team about this but haven't had a definite answer from them whether they want (or don't want) to issue an advisory for this. I'm now convinced this is a security problem because it can result in wrong privileges