Bug#689602: pu: package dbus/1.2.24-4+squeeze2

2013-01-12 Thread Adam D. Barratt
On Thu, 2012-10-04 at 13:56 +0100, Simon McVittie wrote: CVE-2012-3524 (#689070) is a local root privilege escalation vulnerability when setuid-root applications use libdbus without first sanitizing their caller-supplied environment via a whitelist. Applications thought to be exploitable

Bug#689602: pu: package dbus/1.2.24-4+squeeze2

2013-01-12 Thread Simon McVittie
On 12/01/13 16:59, Adam D. Barratt wrote: On Thu, 2012-10-04 at 13:56 +0100, Simon McVittie wrote: CVE-2012-3524 (#689070) is a local root privilege escalation vulnerability ... it looks like applying the patches to unstable / testing was happily uneventful in terms of any issues arising in

Bug#689602: pu: package dbus/1.2.24-4+squeeze2

2013-01-12 Thread Adam D. Barratt
Control: tags -1 + squeeze confirmed On Sat, 2013-01-12 at 17:23 +, Simon McVittie wrote: On 12/01/13 16:59, Adam D. Barratt wrote: On Thu, 2012-10-04 at 13:56 +0100, Simon McVittie wrote: CVE-2012-3524 (#689070) is a local root privilege escalation vulnerability ... it looks like

Bug#689602: pu: package dbus/1.2.24-4+squeeze2

2013-01-12 Thread Simon McVittie
On 12/01/13 17:29, Adam D. Barratt wrote: On Sat, 2013-01-12 at 17:23 +, Simon McVittie wrote: On 12/01/13 16:59, Adam D. Barratt wrote: On Thu, 2012-10-04 at 13:56 +0100, Simon McVittie wrote: CVE-2012-3524 (#689070) is a local root privilege escalation vulnerability

Bug#689602: pu: package dbus/1.2.24-4+squeeze2

2013-01-12 Thread Adam D. Barratt
Control: tags -1 + pending On Sat, 2013-01-12 at 20:50 +, Simon McVittie wrote: On 12/01/13 17:29, Adam D. Barratt wrote: On Sat, 2013-01-12 at 17:23 +, Simon McVittie wrote: On 12/01/13 16:59, Adam D. Barratt wrote: On Thu, 2012-10-04 at 13:56 +0100, Simon McVittie wrote:

Bug#689602: pu: package dbus/1.2.24-4+squeeze2

2012-10-04 Thread Simon McVittie
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: pu CVE-2012-3524 (#689070) is a local root privilege escalation vulnerability when setuid-root applications use libdbus without first sanitizing their caller-supplied environment via a whitelist.