Package: kernel-patch-openmosix
Version: 1:0.3.4-7
Severity: normal
Tags: security

Due to the fact that the OpenMosix kernel patch shares a significant
amount of code with the Mosix kernel patch, chances are this is
vulnerable in the OpenMosix patch as well.

Please communicate with upstream to find out if there is a fix for
this. I know you did say on IRC that the latest patch was for 2.4.26
and that there are most likely many problems with this patch, and that
you "just can't get worked up over problems in 2+ year old software".
If this is still true, then do the users a favor and remove this
package, or put it up for adoption. 

If this does get fixed, please mention the CAN number in the changelog.

Micah

P.S. Additionally, the fact that OpenMosix is something that should
*not* be run on an unsecured network should be prominantly mentioned
in the docs.




-- System Information:
Debian Release: testing/unstable
  APT prefers testing
  APT policy: (990, 'testing'), (300, 'unstable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.8-2-k7
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)

Versions of packages kernel-patch-openmosix depends on:
ii  bash                          3.0-15     The GNU Bourne Again SHell
ii  grep-dctrl                    2.6.7      Grep Debian package information
ii  kernel-patch-scripts          0.99.36    Scripts to help dealing with packa
ii  patch                         2.5.9-2    Apply a diff file to an original

Versions of packages kernel-patch-openmosix recommends:
ii  kernel-package                9.002      A utility for building Linux kerne

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to