Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Manuel Prinz
Hi Moritz! Am Dienstag, den 08.12.2009, 22:28 +0100 schrieb Moritz Muehlenhoff: > You can leave etch and lenny untouched, the impact doesn't warrant an > update. Thanks for clarifying! Best regards Manuel -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Moritz Muehlenhoff
On Tue, Dec 08, 2009 at 09:46:45PM +0100, Manuel Prinz wrote: > Hi Moritz! > > Am Dienstag, den 08.12.2009, 20:35 +0100 schrieb Moritz Muehlenhoff: > > You should rather use the copy of libltdl currently in the > > archive or is there a technical reason, which prevents this? > > I'm aware of that

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Manuel Prinz
Hi Moritz! Am Dienstag, den 08.12.2009, 20:35 +0100 schrieb Moritz Muehlenhoff: > You should rather use the copy of libltdl currently in the > archive or is there a technical reason, which prevents this? I'm aware of that and discussed it with upstream. They said it would require quite some chang

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Moritz Muehlenhoff
On Tue, Dec 08, 2009 at 01:42:23AM +0100, Manuel Prinz wrote: > Here's the debdiff. Changes are checked into our SVN repo. > > Best regards > Manuel You should rather use the copy of libltdl currently in the archive or is there a technical reason, which prevents this? Cheers, Moritz -

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Luk Claes
Manuel Prinz wrote: > Hi Michael! > > Am Montag, den 07.12.2009, 00:06 -0500 schrieb Michael Gilbert: >> The following CVE (Common Vulnerabilities & Exposures) id was >> published for libtool. I have determined that this package embeds a >> vulnerable copy of the libtool source code. However, si

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Manuel Prinz
Here's the debdiff. Changes are checked into our SVN repo. Best regards Manuel diff -u openmpi-1.3.3/debian/changelog openmpi-1.3.3/debian/changelog --- openmpi-1.3.3/debian/changelog +++ openmpi-1.3.3/debian/changelog @@ -1,3 +1,10 @@ +openmpi (1.3.3-4) unstable; urgency=medium + + * Fixed secur

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Manuel Prinz
Hi Michael! Am Montag, den 07.12.2009, 00:06 -0500 schrieb Michael Gilbert: > The following CVE (Common Vulnerabilities & Exposures) id was > published for libtool. I have determined that this package embeds a > vulnerable copy of the libtool source code. However, since this is a > mass bug fili

Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Manuel Prinz
Am Montag, den 07.12.2009, 09:30 +0100 schrieb Sylvestre Ledru: > Manuel, are you going to handle this issue or do you want me to do it ? I can take care of that. I've forwarded this upstream already. The best option would be having a fixed libtool available, or trying to use the backported patch

Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Sylvestre Ledru
Le lundi 07 décembre 2009 à 13:30 +0100, Manuel Prinz a écrit : > Am Montag, den 07.12.2009, 09:30 +0100 schrieb Sylvestre Ledru: > > Manuel, are you going to handle this issue or do you want me to do it ? > > I can take care of that. I've forwarded this upstream already. The best > option would b

Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Sylvestre Ledru
Manuel, are you going to handle this issue or do you want me to do it ? Thanks Sylvestre Le lundi 07 décembre 2009 à 00:06 -0500, Michael Gilbert a écrit : > Package: openmpi > Severity: grave > Tags: security > > Hi, > > The following CVE (Common Vulnerabilities & Exposures) id was > published

Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-06 Thread Michael Gilbert
Package: openmpi Severity: grave Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) id was published for libtool. I have determined that this package embeds a vulnerable copy of the libtool source code. However, since this is a mass bug filing (due to so many packages emb