Bug#429225: [CVE-2007-3100] local DoS through insecure semaphore

2007-06-16 Thread Philipp Hug
I'll upload a new upstream version to unstable today with a fix for CVS-2007-3100 included. I also prepared a fix for etch. greetings philipp -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#429225: [CVE-2007-3100] local DoS through insecure semaphore

2007-06-16 Thread Florian Weimer
Package: open-iscsi Tags: security A minor DoS vulnerability has been discovered in open-iscsi: | usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) before | 2.0-865 uses a semaphore with insecure permissions | (world-writable/world-readable) for managing log messages using shared | memory