Re: Bug#839607: Robustify manager_dispatch_notify_fd()

2016-10-03 Thread Florian Weimer
* Salvatore Bonaccorso: > There were two CVE assingments for systemd recently, CVE-2016-7795 and > CVE-2016-7796, and assigned here: > https://marc.info/?l=oss-security&m=147521835218986&w=2 > > CVE-2016-7795 is for > > https://github.com/systemd/systemd/issues/4234 > https://www.agwa.name/blog/po

Re: Bug#839607: Robustify manager_dispatch_notify_fd()

2016-10-03 Thread Salvatore Bonaccorso
Hi, On Mon, Oct 03, 2016 at 12:48:15PM +0200, Florian Weimer wrote: > * Michael Biebl: > > > Dear security team, I'd appreciate your input on bug #839607 > > It's a bug, and it should be fixed in stable, probably in a point > update. Agreed, and fixing via point release seems okay. > Does this

Re: Bug#839607: Robustify manager_dispatch_notify_fd()

2016-10-03 Thread Florian Weimer
* Michael Biebl: > Dear security team, I'd appreciate your input on bug #839607 It's a bug, and it should be fixed in stable, probably in a point update. Does this affect other distributions? In this case, it's best to request a CVE ID on the oss-security list.

Re: Bug#839607: Robustify manager_dispatch_notify_fd()

2016-10-03 Thread Michael Biebl
Am 03.10.2016 um 12:11 schrieb Michael Biebl: > Am 03.10.2016 um 08:22 schrieb Wolfgang Karall: >> Hello Michael, >> >> On 16-10-02 22:36:00, Michael Biebl wrote: >>> The news about systemd crashing when getting a zero sized message >>> on the notification socket made the rounds recently. While v2

Re: Bug#839607: Robustify manager_dispatch_notify_fd()

2016-10-03 Thread Michael Biebl
Am 03.10.2016 um 12:11 schrieb Michael Biebl: > Am 03.10.2016 um 08:22 schrieb Wolfgang Karall: >> Hello Michael, >> >> On 16-10-02 22:36:00, Michael Biebl wrote: >>> The news about systemd crashing when getting a zero sized message >>> on the notification socket made the rounds recently. While v2

Bug#839607: Robustify manager_dispatch_notify_fd()

2016-10-02 Thread Michael Biebl
Package: systemd Version: 215-17+deb8u5 Severity: important User: pkg-systemd-maintain...@lists.alioth.debian.org Usertags: jessie-backport The news about systemd crashing when getting a zero sized message on the notification socket made the rounds recently. While v215 is not directly affected by