Re: [pve-devel] CVE-2015-5154

2015-07-27 Thread Dietmar Maurer
> When can we expect a fix in pvetest repositories? its already there (pvetest and pve-no-subscription) - please test. ___ pve-devel mailing list pve-devel@pve.proxmox.com http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-devel

Re: [pve-devel] CVE-2015-5154

2015-07-27 Thread Henry Spanka
When can we expect a fix in pvetest repositories? -- Fügen Sie uns in die Liste "vertrauenswürdiger Absender" hinzu. If you have any further questions, please let us know. Mit freundlichen Grüßen / With best regards myVirtualserver.de | Development Team Henry Spanka

Re: [pve-devel] CVE-2015-5154

2015-07-27 Thread Alexandre DERUMIER
>>to answer myself. PVE is affected. Every VM with a CDROM can get root. yes, indeed :( https://access.redhat.com/security/cve/CVE-2015-5154 - Mail original - De: "Stefan Priebe" À: "pve-devel" Envoyé: Lundi 27 Juillet 2015 15:39:54 Objet: Re: [pve-devel

Re: [pve-devel] CVE-2015-5154

2015-07-27 Thread Stefan Priebe - Profihost AG
to answer myself. PVE is affected. Every VM with a CDROM can get root. Stefan Am 27.07.2015 um 14:36 schrieb Stefan Priebe - Profihost AG: > Hi, > > does this affect proxmox? I don't understand why xen is explicit content > of the advisory. > http://seclists.org/oss-sec/2015/q3/212 > > -- > Ste

[pve-devel] CVE-2015-5154

2015-07-27 Thread Stefan Priebe - Profihost AG
Hi, does this affect proxmox? I don't understand why xen is explicit content of the advisory. http://seclists.org/oss-sec/2015/q3/212 -- Stefan ___ pve-devel mailing list pve-devel@pve.proxmox.com http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-deve