#please unsubscribe me from this list # i do not find any link to do so. # thank you.
end comments On Mon, Aug 6, 2012 at 10:50 AM, Moritz Muehlenhoff <[email protected]> wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > - ------------------------------------------------------------------------- > Debian Security Advisory DSA-2523-1 [email protected] > http://www.debian.org/security/ Moritz Muehlenhoff > August 06, 2012 http://www.debian.org/security/faq > - ------------------------------------------------------------------------- > > Package : globus-gridftp-server > Vulnerability : programming error > Problem type : remote > Debian-specific: no > CVE ID : CVE-2012-3292 > > It was discovered that the GridFTP component from the Globus Toolkit, a > toolkit used for building Grid systems and applications performed > insufficient validation of a name lookup, which could lead to privilege > escalation. > > For the stable distribution (squeeze), this problem has been fixed in > version 3.23-1+squeeze1 of the globus-gridftp-server source package > and in version 0.43-1+squeeze1 of the globus-gridftp-server-control > source package > > For the testing distribution (wheezy) and the unstable distribution (sid), > this problem has been fixed in version 6.5-1. > > We recommend that you upgrade your globus-gridftp-server packages. > > Further information about Debian Security Advisories, how to apply > these updates to your system and frequently asked questions can be > found at: http://www.debian.org/security/ > > Mailing list: [email protected] > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.12 (GNU/Linux) > > iEYEARECAAYFAlAgA60ACgkQXm3vHE4uylrLBQCeLQK4sg0nIec6aLwLd4oAsCft > qPcAoOZJExFHln29zwfHuDP+Yvy9vNZN > =zk2z > -----END PGP SIGNATURE----- > > > -- > To UNSUBSCRIBE, email to [email protected] > with a subject of "unsubscribe". Trouble? Contact > [email protected] > Archive: > http://lists.debian.org/[email protected] > >

