Bug#1010303: networkd-dispatcher: CVE-2022-29799 CVE-2022-29800

2022-05-03 Thread Salvatore Bonaccorso
Hi Julian, On Tue, May 03, 2022 at 06:22:37PM +0200, Julian Andres Klode wrote: > On Tue, May 03, 2022 at 08:47:56AM -0700, Clayton Craft wrote: > > Hi folks, > > > > > what is the story there? I don't believe any of those MS reports > > > are actually (important) security issues, > > > > The

Bug#1010303: networkd-dispatcher: CVE-2022-29799 CVE-2022-29800

2022-05-03 Thread Clayton Craft
On Tue, 03 May 2022 18:22:37 +0200 Julian Andres Klode wrote: > So the way this usually goes is that distros also get notified, and > fixes are held back until a date (well hour really) coordinated by the > distros so everyone can release fixes at the same time, by way of > contacting the distros

Bug#1010303: networkd-dispatcher: CVE-2022-29799 CVE-2022-29800

2022-05-03 Thread Julian Andres Klode
On Tue, May 03, 2022 at 08:47:56AM -0700, Clayton Craft wrote: > Hi folks, > > > what is the story there? I don't believe any of those MS reports > > are actually (important) security issues, > > The issue is basically that microsoft and/or their customers are allowing > arbitrary code execution

Bug#1010303: networkd-dispatcher: CVE-2022-29799 CVE-2022-29800

2022-05-03 Thread Clayton Craft
Hi folks, > what is the story there? I don't believe any of those MS reports > are actually (important) security issues, The issue is basically that microsoft and/or their customers are allowing arbitrary code execution under a system user account (the same one that normally runs

Bug#1010303: networkd-dispatcher: CVE-2022-29799 CVE-2022-29800

2022-05-03 Thread Julian Andres Klode
Hi Clayton (CC), what is the story there? I don't believe any of those MS reports are actually (important) security issues, also why was this being disclosed publicly rather than responsibly? The fixes for the alleged permission issue also only handles one parent directory and classic

Bug#1010303: networkd-dispatcher: CVE-2022-29799 CVE-2022-29800

2022-05-03 Thread Julian Andres Klode
On Thu, Apr 28, 2022 at 01:53:58PM +0200, Salvatore Bonaccorso wrote: > Source: networkd-dispatcher > Version: 2.1-2 > Severity: grave > Tags: security upstream > X-Debbugs-Cc: car...@debian.org, Debian Security Team > > > Hi, > > The following vulnerabilities were published for

Bug#1010303: networkd-dispatcher: CVE-2022-29799 CVE-2022-29800

2022-04-28 Thread Salvatore Bonaccorso
Source: networkd-dispatcher Version: 2.1-2 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerabilities were published for networkd-dispatcher. CVE-2022-29799[0] and CVE-2022-29800[1]. If you fix the vulnerabilities please