Bug#734789: [CVE-2013-7284] Remote pre-authentication code execution in PlRPC

2014-04-22 Thread Aníbal Monsalve Salazar
On Sun, 2014-04-06 11:12:17 +0200, Moritz Mühlenhoff wrote: > On Sat, Mar 29, 2014 at 09:07:11AM +1100, Aníbal Monsalve Salazar wrote: >> On Fri, 2014-03-28 16:22:14 +0100, Moritz Muehlenhoff wrote: >>> On Thu, Jan 09, 2014 at 09:01:53PM +0100, Florian Weimer wrote: Package: libplrpc-perl

Bug#734789: [CVE-2013-7284] Remote pre-authentication code execution in PlRPC

2014-04-21 Thread Salvatore Bonaccorso
Hi all, On Sun, Apr 06, 2014 at 11:12:17AM +0200, Moritz Mühlenhoff wrote: > On Sat, Mar 29, 2014 at 09:07:11AM +1100, Aníbal Monsalve Salazar wrote: > > On Fri, 2014-03-28 16:22:14 +0100, Moritz Muehlenhoff wrote: > > > On Thu, Jan 09, 2014 at 09:01:53PM +0100, Florian Weimer wrote: > > >> Packag

Bug#734789: [CVE-2013-7284] Remote pre-authentication code execution in PlRPC

2014-04-06 Thread Moritz Mühlenhoff
On Sat, Mar 29, 2014 at 09:07:11AM +1100, Aníbal Monsalve Salazar wrote: > On Fri, 2014-03-28 16:22:14 +0100, Moritz Muehlenhoff wrote: > > On Thu, Jan 09, 2014 at 09:01:53PM +0100, Florian Weimer wrote: > >> Package: libplrpc-perl > >> Severity: grave > >> Version: 0.2020-2 > >> Tags: security ups

Bug#734789: [CVE-2013-7284] Remote pre-authentication code execution in PlRPC

2014-03-28 Thread Aníbal Monsalve Salazar
On Fri, 2014-03-28 16:22:14 +0100, Moritz Muehlenhoff wrote: > On Thu, Jan 09, 2014 at 09:01:53PM +0100, Florian Weimer wrote: >> Package: libplrpc-perl >> Severity: grave >> Version: 0.2020-2 >> Tags: security upstream >> >> The PlRPC module uses Storable in an unsafe way, leading to a remote >>

Bug#734789: [CVE-2013-7284] Remote pre-authentication code execution in PlRPC

2014-03-28 Thread Moritz Muehlenhoff
On Thu, Jan 09, 2014 at 09:01:53PM +0100, Florian Weimer wrote: > Package: libplrpc-perl > Severity: grave > Version: 0.2020-2 > Tags: security upstream > > The PlRPC module uses Storable in an unsafe way, leading to a remote > code execution vulnerability (in both the client and the server). > >

Bug#734789: [CVE-2013-7284] Remote pre-authentication code execution in PlRPC

2014-01-09 Thread Florian Weimer
Package: libplrpc-perl Severity: grave Version: 0.2020-2 Tags: security upstream The PlRPC module uses Storable in an unsafe way, leading to a remote code execution vulnerability (in both the client and the server). Upstream bug report: https://rt.cpan.org/Public/Bug/Display.html?id=90474 A fix