Re: [SECURITY] [DSA 1494-1] New linux-2.6 packages fix privilege escalation

2008-02-11 Thread Adam D. Barratt
On Mon, 2008-02-11 at 18:09 -0500, Simon Valiquette wrote: > Florian Weimer un jour écrivit: > > > > Package: linux-2.6 > > Vulnerability : missing access checks > > Problem type : local > > Debian-specific: no > > CVE Id(s) : CVE-2008-0010 CVE-2008-0163 CVE-2008-0600 [...] >

Re: [SECURITY] [DSA 1494-1] New linux-2.6 packages fix privilege escalation

2008-02-11 Thread Simon Valiquette
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 Florian Weimer un jour écrivit: > > Package: linux-2.6 > Vulnerability : missing access checks > Problem type : local > Debian-specific: no > CVE Id(s) : CVE-2008-0010 CVE-2008-0163 CVE-2008-0600 > In the vserver-enabled kernels

Re: [Fwd: [Xen-users] patch for kernel exploit?]

2008-02-11 Thread Bastian Blank
On Mon, Feb 11, 2008 at 09:48:24AM +, Michael D. Norwick wrote: > Found this on the xen-users list this morning. Has this been addressed > in Debian yet? Yes, it is fixed in DSA 1494. Bastian -- Each kiss is as the first. -- Miramanee, Kirk's wife, "The Paradise Syndrome",

Re: Testers needed: nagios-plugins

2008-02-11 Thread Moritz Muehlenhoff
On 2008-02-10, Moritz Muehlenhoff <[EMAIL PROTECTED]> wrote: > I need testers for a nagios-plugins security update: > http://people.debian.org/~jmm/nagios/ (sarge and etch packages) > > Please report both failures and success to [EMAIL PROTECTED] Thanks for the various test reports, an update wil

Re: Testers needed: nagios-plugins

2008-02-11 Thread Jochen Bartl
Hi, I have tested the etch/i386 packages today at work on our nagios development server. I haven't recognized any problems with the packages until now. best regards, jochen On Sun, 2008-02-10 at 22:54 +0100, Moritz Muehlenhoff wrote: > I need testers for a nagios-plugins security update: > ht

Re: [Fwd: [Xen-users] patch for kernel exploit?]

2008-02-11 Thread Fabio La Farcioli
Michael D. Norwick ha scritto: Found this on the xen-users list this morning. Has this been addressed in Debian yet? Michael There is a workaround for the bug: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464953 -- Fabio La Farcioli[EMAIL PROTECTED] Molino Alimonti S

[Fwd: [Xen-users] patch for kernel exploit?]

2008-02-11 Thread Michael D. Norwick
Found this on the xen-users list this morning. Has this been addressed in Debian yet? Michael --- Begin Message --- Hi, As most of you probably already know, a local root exploit was released yesterday which affects kernels from 2.6.17 to 2.6.24.1. Is there an official patch for dom0 and do