Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Raphael Geissert
Charles Plessy wrote: > Le Mon, Aug 25, 2008 at 07:16:00AM +0200, Christian Perrier a écrit : >> >> - timing wrt the release >> - timing wrt the "half of the developers are VAC" status we generally >> have in August >> - the obvious lack of preparation > > In addition, security issues should b

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Moritz Muehlenhoff
Christian Perrier wrote: >> This is far below the quality I expect from a mass bug filing that's been >> reviewed by debian-devel. Mass bugfilings at RC severity need to be held to > > Even though I overread the thread when Dmitry posted his intent to > -devel, I feel like there was *no* strong a

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Charles Plessy
Le Mon, Aug 25, 2008 at 07:16:00AM +0200, Christian Perrier a écrit : > > - timing wrt the release > - timing wrt the "half of the developers are VAC" status we generally > have in August > - the obvious lack of preparation In addition, security issues should better be reported upstream first s

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Neil Williams
On Mon, 2008-08-25 at 10:09 +0200, Thijs Kinkhorst wrote: > On Sunday 24 August 2008 22:00, Steve Langasek wrote: > > Please take responsibility for providing the missing information to the > > package maintainers, and for correcting the false positives that you've > > filed. > > Yes, please. I th

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Neil Williams
On Mon, 2008-08-25 at 10:09 +0200, Thijs Kinkhorst wrote: > On Sunday 24 August 2008 22:00, Steve Langasek wrote: > > Please take responsibility for providing the missing information to the > > package maintainers, and for correcting the false positives that you've > > filed. > > Yes, please. I th

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Dmitry E. Oboukhov
TK>> Quoting Steve Langasek ([EMAIL PROTECTED]): TK>>> This is far below the quality I expect from a mass bug filing that's been TK>>> reviewed by debian-devel. Mass bugfilings at RC severity need to be held TK>>> to TK>> TK>> Even though I overread the thread when Dmitry posted his intent to TK>

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Thijs Kinkhorst
On Sunday 24 August 2008 22:00, Steve Langasek wrote: > Please take responsibility for providing the missing information to the > package maintainers, and for correcting the false positives that you've > filed. Yes, please. I think the only way the damage of this bad bug filing can be mitigated i

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Thijs Kinkhorst
On Monday 25 August 2008 07:16, Christian Perrier wrote: > Quoting Steve Langasek ([EMAIL PROTECTED]): > > This is far below the quality I expect from a mass bug filing that's been > > reviewed by debian-devel. Mass bugfilings at RC severity need to be held > > to > > Even though I overread the th

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Christian Perrier
Quoting Steve Langasek ([EMAIL PROTECTED]): > This is far below the quality I expect from a mass bug filing that's been > reviewed by debian-devel. Mass bugfilings at RC severity need to be held to Even though I overread the thread when Dmitry posted his intent to -devel, I feel like there was

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
On Sun, Aug 24, 2008 at 10:05:30PM +0400, Dmitry E. Oboukhov wrote: > Package: initramfs-tools > Severity: grave > This message about the error concerns a few packages at once. I've > tested all the packages (for Lenny) on my Debian mirror. All scripts > of packages (marked as executable) we