Re: Kernel upgrade for 3Ware Driver issues?

2008-04-22 Thread dann frazier
On Tue, Apr 22, 2008 at 04:45:53PM -0600, Michael Loftis wrote: > > > --On April 22, 2008 11:21:25 PM +0200 Florian Weimer <[EMAIL PROTECTED]> > wrote: > > >> >> I guess the number of systems with amd64 and a 3ware 7xxx/8 PATA >> controllers is pretty small, otherwise this bug would have been

Re: [SECURITY] [DSA 1554-1] New roundup packages fix cross-site scripting vulnera

2008-04-22 Thread Brad Dondale
I have started 2 weeks holidays. If you have any technical support requests, please create a ticket with your online ticket system. Thanks! -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Kernel upgrade for 3Ware Driver issues?

2008-04-22 Thread Michael Loftis
--On April 22, 2008 11:21:25 PM +0200 Florian Weimer <[EMAIL PROTECTED]> wrote: I guess the number of systems with amd64 and a 3ware 7xxx/8 PATA controllers is pretty small, otherwise this bug would have been noticed earlier. So the sky is not falling. Technically, this is not a secu

Re: Kernel upgrade for 3Ware Driver issues?

2008-04-22 Thread Florian Weimer
* Michael Loftis: > The 2.6.18-6 kernel has a buggy 3w- driver. Causes data > corruption on (at least) EM64T w/ 4+GB of RAM. I'm also pretty sure > it's the cause of corruption on EM64T systems in 32-bit mode even w/o > 4+GB of RAM. Specifically it affects 7xxx and 8xxx series cards. > >

Re: Request a security audit for my xiterm+thai package.

2008-04-22 Thread Neutron Soutmun
> I have no time auditing this bug one thing came to my mind > when I had a look in main.c: > 1655 if ((display_name = getenv ("DISPLAY")) == NULL) > 1656 display_name = ":0"; > > Please fix that code to print an error, see: > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1692 and