Bug#730518: kfreebsd-10: CVE-2013-6832 nand memory leak in ioctl

2013-11-26 Thread Robert Millan
On 26/11/2013 03:36, Steven Chamberlain wrote:
 Package: kfreebsd-10
 Version: 10.0~svn257123-1
 Severity: grave
 Tags: security fixed-upstream
 Control: fixed -1 kfreebsd-10/10.0~svn234760-1
 
 http://seclists.org/bugtraq/2013/Nov/73
 
 The nand driver was introduced into kfreebsd-10 by r235537.
 It is not included in kfreebsd-9 or kfreebsd-8 packages.
 
 Fixed by upstream SVN commits r258387 and r258425.

Those are the head commits (both included in latest kfreebsd-11 upload).

As for stable/10 it seems to me that r258554 includes MFC of both
problems. Please can you confirm?

-- 
Robert Millan


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#730518: kfreebsd-10: CVE-2013-6832 nand memory leak in ioctl

2013-11-26 Thread Steven Chamberlain
On 26/11/13 10:44, Robert Millan wrote:
 Those are the head commits (both included in latest kfreebsd-11 upload).

I forgot about kfreebsd-11.  11.0~svn256281-1 was affected but
11.0~svn258494-1 is already fixed.

 As for stable/10 it seems to me that r258554 includes MFC of both
 problems. Please can you confirm?

I should have pointed to this.  Yes, the MFC to stable/10/ (r258554) has
both of these commits (the actual bugfix, and then fixing compiler
warnings).

Regards,
-- 
Steven Chamberlain
ste...@pyro.eu.org


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#730518: kfreebsd-10: CVE-2013-6832 nand memory leak in ioctl

2013-11-25 Thread Steven Chamberlain
Package: kfreebsd-10
Version: 10.0~svn257123-1
Severity: grave
Tags: security fixed-upstream
Control: fixed -1 kfreebsd-10/10.0~svn234760-1

http://seclists.org/bugtraq/2013/Nov/73

The nand driver was introduced into kfreebsd-10 by r235537.
It is not included in kfreebsd-9 or kfreebsd-8 packages.

Fixed by upstream SVN commits r258387 and r258425.

-- System Information:
Debian Release: 7.1
  APT prefers proposed-updates
  APT policy: (500, 'proposed-updates'), (500, 'stable')
Architecture: kfreebsd-amd64 (x86_64)

Kernel: kFreeBSD 9.0-2-amd64-xenhvm
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: Re: Bug#730518: kfreebsd-10: CVE-2013-6832 nand memory leak in ioctl

2013-11-25 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 found 730518 kfreebsd-10/10.0~svn237137-1
Bug #730518 [kfreebsd-10] kfreebsd-10: CVE-2013-6832 nand memory leak in ioctl
Marked as found in versions kfreebsd-10/10.0~svn237137-1.
 thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
730518: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=730518
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems


--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org