Bug#552433: Fwd: Bug#552433: libnss-ldapd: ignores case of uids

2009-11-22 Thread Arthur de Jong
On Thu, 2009-11-05 at 21:07 +0100, Arthur de Jong wrote: > I will contact the security team and prepare an update. I am awaiting a response from the security team whether to do this via a security update or via proposed-updates. An updated 0.6.7.2 package is being prepared here: http://arthurdejo

Bug#552433: Fwd: Bug#552433: libnss-ldapd: ignores case of uids

2009-11-05 Thread Arthur de Jong
On Thu, 2009-11-05 at 17:32 +0100, Petter Reinholdtsen wrote: > I really hope you find time to fix this in Lenny, as it affects Debian > Edu. The issue is also a security issue, where users can by-pass > netgroup based limitations by changing the case of the username they use > when logging in. S

Bug#552433: Fwd: Bug#552433: libnss-ldapd: ignores case of uids

2009-11-05 Thread Petter Reinholdtsen
[Arthur de Jong] > Thanks for pointing this out and providing the link. I will contact > the security team and prepare an update. Great. :) > It is strange though that the group membership is lost because I > would think those lookups would also be case-insensitive. I noticed > the case-insensiti

Bug#552433: Fwd: Bug#552433: libnss-ldapd: ignores case of uids

2009-10-29 Thread Arthur de Jong
Dear stable release team, A user reported a bug (#552433) against libnss-ldapd which causes some problems and asked if a fix can be made available in a stable update. I can probably backport the fix to version 0.6.7.1 but I wanted to know if such a fix will be considered a candidate for proposed-