Bug#476536: grub-pc: allow update-grub to do not generate single-user entry if not desired

2008-04-21 Thread Lubomir Kundrak
better than in GRUB Legacy case in case this happens). For now, I'm going to import the patch into package proposed to Fedora and am wishing the GRUB upstream good luck in becoming a good Free Software Community citizen :) Thanks, -- Lubomir Kundrak (Red Hat Security Response Team)

Bug#471511: gnome-keyring-manager: clear-text passwords shown without protection

2008-03-18 Thread Lubomir Kundrak
client's memory if you keep it running, etc.). That's the basic principle: *Never* let anyone who you do not trust use your desktop. Log off or lock screen when you leave the terminal. -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Bug#469296:

2008-03-04 Thread Lubomir Kundrak
Wow, you really consider is a security issue? When a user does a mistake? -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#462047: iceweasel: crash/exploit

2008-01-22 Thread Lubomir Kundrak
the attack took place). Do you have a public IP address and do you run any network servers? Do you happen to run any other network clients apart from Web browser, such as BitTorrent client or maybe an Instant Messenger? Thanks, -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE

Bug#461075: uw-imapd: world-writable tmp files

2008-01-18 Thread Lubomir Kundrak
*/ 1319 sprintf (lock,%s/.%lx.%lx,closedBox ? : tmpdir, 1320(unsigned long) sbuf-st_dev,(unsigned long) sbuf-st_ino); -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#435413: oops when Windows server sent bad domain name null terminator

2008-01-02 Thread Lubomir Kundrak
for this particular Unicode, UCS-16, string). Thus -- this needs voluntary cooperation of user who already has root provileges (mount a smb share) and can cause a harmless oops triggerable only at mount time. Regards, -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL

Bug#454092: pm-suspend expands *

2007-12-03 Thread Lubomir Kundrak
elif [ -x /usr/lib/pm-utils/sleep.d/$base ]; then 71 echo /usr/lib/pm-utils/sleep.d/$base 72 fi 73 done Thanks, -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Bug#449108: CVE-2007-3920: bypass password authentication

2007-11-05 Thread Lubomir Kundrak
Whoops, I am terribly sorry for the noise. In fact I did not notice that this is a different patch from proposed upstream one and is likely to be correct. -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble

Bug#449108: CVE-2007-3920: bypass password authentication

2007-11-05 Thread Lubomir Kundrak
Please note that Red Hat believes that the attached patch is not completly correct. See the Red Hat bugzilla entry for justification and another patch: https://bugzilla.redhat.com/show_bug.cgi?id=350271 -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL

Bug#448186: silc+irssi gime me segment fault

2007-10-29 Thread Lubomir Kundrak
Andres: Do you have a core dump? Are you able to produce a reasonable backtrace? Could you please how to reproduce the problem in more detail? Thanks, -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble

Bug#438511: CVE-2007-3713 CenterICQ buffer overflows

2007-08-20 Thread Lubomir Kundrak
Hi, Here is the diff of changes we did to fix this for Fedora: [1]. Hopefully that will be useful also for you. [1] http://cvs.fedora.redhat.com/viewcvs/rpms/centericq/devel/centericq-4.21.0-overflows.patch?root=extras Regards, -- .''`. Lubomir Kundrak (Red Hat Security Response Team

Bug#428770: Sudo bug

2007-06-14 Thread Lubomir Kundrak
to compromise an account using another vulnerability. In that case he has also numerous others way to stole that user's privilegies by tricking the user using sudo or anything similar. (Trojans, etc.) -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL

Bug#422606: spamc problem connectind to spamd

2007-05-09 Thread Lubomir Kundrak
Arnfinn, it seems like many spamds spawned, but did not finish. Could you please check what are they doing -- i.e. which message are they trying to check and whether the hang can be reproduced with that message? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe.

Bug#416934: Off-by-one in python's locale.strxfrm()

2007-04-02 Thread Lubomir Kundrak
of strxfrm() is never meant to be displayed to the user. -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#408530: libcapi20-3: buffer overflow in printbuf called from capi_cmsg2str

2007-01-29 Thread Lubomir Kundrak
/source/xref/isdn4k-utils-CVS-2003-09-23/capi20/convert.c#957 Regards, -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#408432: CVE-2007-0493 Bind after-free() use patch

2007-01-26 Thread Lubomir Kundrak
Here's a patch for two of the issues fixed by the new release. Anyone isolated a patch for CVE-2007-0494? -- Lubomir Kundrak (Red Hat Security Response Team) $ FILES= lib/dns/include/dns/validator.h lib/dns

Bug#228174: Galeon (Mozilla?) defaults to weakest authentication method

2007-01-02 Thread Lubomir Kundrak
This issue is already assigned a CVE-2005-2395. The upstream BTS entry is https://bugzilla.mozilla.org/show_bug.cgi?id=281851 -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#402951: libapache-mod-ssl: restart leaves /var/cache/apache/__db.ssl_cache.db there

2006-12-21 Thread Lubomir Kundrak
manage to get any more information concerning this? Regards, -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#290435: rmt filename support makes tar vulnerable to phishing attacks

2006-11-30 Thread Lubomir Kundrak
This is a documented behavior. --force-local should be used in case user wants to unpack local file whose name contains a colon character. -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

Bug#396360: CVE-2006-4513 Abiword likely vulnerable to integer overflows

2006-10-31 Thread Lubomir Kundrak
Package: abiword Version: 2.2.7-3sarge2 Tags: security, upstream Severity: grave Abiword likely uses version of VW library (see #396256) vulnerable to two integer overflow conditions. See CVE text for more details. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4513 -- Lubomir Kundrak

Bug#396256: CVE-2006-4513: wvWare Multiple Integer Overflow Vulnerabilities

2006-10-31 Thread Lubomir Kundrak
This also affects AbiWord package. In contrast to what CVE candidate CVE-2006-4513 text says, this does _not_ affect KOffice's KWord. -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL