Bug#1022025: Upstream Reports

2022-10-21 Thread Christoph Zechner
On Thu, 20 Oct 2022 18:36:21 +0200 Diederik de Haas wrote: On Thursday, 20 October 2022 17:36:33 CEST Christoph Zechner wrote: > I hope this helps, if there's something additional I could contribute, > please let me know! It's probably best to participate in the upstream i

Bug#1022025: Upstream Reports

2022-10-20 Thread Christoph Zechner
amdgpu: finishing device. Afterwards, I booted my freshly built 5.10.0-19 kernel with "nomodeset" and was able to log in via X, but the two displays attached to my laptop did not work, only my internal panel. I hope this helps, if there's something additional I could contribute, please let me know! Best regards Christoph Zechner

Bug#996778: xymon-client: disable logfetch's ability to execute arbitrary code

2021-10-18 Thread Christoph Zechner
Hi, On 18/10/2021 21:55, Axel Beckert wrote: Hi again, Christoph Zechner wrote: Severity: critical This is clearly not "critical". Myon already fixed that. Apologies for that, I was not sure how to classify it, but since it was a security-related issue, I thought it was a

Bug#996778: xymon-client: disable logfetch's ability to execute arbitrary code

2021-10-18 Thread Christoph Zechner
bitrary code [1]. This can and should be prevented by default by using LOGFETCHOPTS="--noexec" instead. Best regards Christoph Zechner patch: --- xymonclient.cfg.DISt +++ xymonclient.cfg.PATCHED @@ -18,7 +18,7 @@ include /var/run/xymon/xymonclient-include.cfg # Options to logfetc