Bug#858768: apparmor: CVE-2017-6507

2017-03-28 Thread Salvatore Bonaccorso
Hi! On Tue, Mar 28, 2017 at 02:27:35PM +0200, intrigeri wrote: > Hi, > > Antoine Beaupre: > > Jessie, on the other hand, does not seem to be vulnerable: > > From my reading of the code, it seems that Wheezy, Jessie and Stretch > are all vulnerable, but only when using sysvinit. I've just fixed t

Bug#858768: apparmor: CVE-2017-6507

2017-03-28 Thread intrigeri
Hi, Antoine Beaupre: > Jessie, on the other hand, does not seem to be vulnerable: >From my reading of the code, it seems that Wheezy, Jessie and Stretch are all vulnerable, but only when using sysvinit. I've just fixed this issue in sid, and filed an unblock request for Stretch. But systems runn

Bug#858768: apparmor: CVE-2017-6507

2017-03-28 Thread intrigeri
Antoine Beaupre: > Here's some more information about that security issue that I could > gleam from testing and other sources. Thanks! I intend to work on this today, but certainly wouldn't mind if one of my team-mates took the lead on it (after coordinating with me so we avoid duplicating work :

Bug#858768: apparmor: CVE-2017-6507

2017-03-27 Thread Antoine Beaupre
Control: found -1 2.7.103-4 Control: notfound -1 2.9.0-3 Here's some more information about that security issue that I could gleam from testing and other sources. To reproduce this in wheezy, you first need to install apparmor: apt-get install apparmor apparmor-profiles sed -i -e 's/GRUB_CMDLINE

Bug#858768: apparmor: CVE-2017-6507

2017-03-26 Thread Salvatore Bonaccorso
Source: apparmor Version: 2.11.0-2 Severity: important Tags: security upstream Forwarded: https://launchpad.net/bugs/1668892 Hi, the following vulnerability was published for apparmor. CVE-2017-6507[0]: | An issue was discovered in AppArmor before 2.12. Incorrect handling of | unknown AppArmor p