Bug#700923: pacemaker: CVE-2013-0281

2013-08-07 Thread Salvatore Bonaccorso
Hi Martin, On Tue, Feb 19, 2013 at 12:35:43PM +0100, Moritz Muehlenhoff wrote: > Package: pacemaker > Severity: grave > Tags: security > Justification: user security hole > > Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0281 for > details > and a link to the upstream fix. It

Bug#700923: [Secure-testing-team] Bug#700923: pacemaker: CVE-2013-0281

2013-03-02 Thread Thijs Kinkhorst
severity 700923 important thanks Hi, I find it unlikely that in serious deployments remote cib management would be enabled for untrusted connections. This kind of management usually happens over separate networks or is appropriately guarded by other controls. And where not, the worst result is

Bug#700923: [Secure-testing-team] Bug#700923: pacemaker: CVE-2013-0281

2013-03-01 Thread Yves-Alexis Perez
On mar., 2013-02-19 at 12:35 +0100, Moritz Muehlenhoff wrote: > Package: pacemaker > Severity: grave > Tags: security > Justification: user security hole > > Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0281 for > details > and a link to the upstream fix. > > Due to the Wheezy

Bug#700923: pacemaker: CVE-2013-0281

2013-02-19 Thread Moritz Muehlenhoff
Package: pacemaker Severity: grave Tags: security Justification: user security hole Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0281 for details and a link to the upstream fix. Due to the Wheezy freeze please apply a minimal fix and request an unblock with the release managers