Bug#871321: tenshi: CVE-2017-11746: should create its PID file before dropping privileges

2019-06-10 Thread Andreas Beckmann
Followup-For: Bug #871321 Hi, I'm rising the severity to serious because tenshi violates version ordering constraints since this bug was fixed in wheezy-security: tenshi | 0.13-2| wheezy | source, all tenshi | 0.13-2| stretch | source, all tenshi | 0.13-2

Bug#871321: tenshi: CVE-2017-11746: should create its PID file before dropping privileges

2017-10-02 Thread Moritz Muehlenhoff
On Mon, Aug 07, 2017 at 05:54:07PM +0200, Salvatore Bonaccorso wrote: > Source: tenshi > Version: 0.13-2 > Severity: normal > Tags: upstream patch security > Forwarded: https://github.com/inversepath/tenshi/issues/6 > > Hi, > > the following vulnerability was published for tenshi. > >

Bug#871321: tenshi: CVE-2017-11746: should create its PID file before dropping privileges

2017-08-07 Thread Salvatore Bonaccorso
Source: tenshi Version: 0.13-2 Severity: normal Tags: upstream patch security Forwarded: https://github.com/inversepath/tenshi/issues/6 Hi, the following vulnerability was published for tenshi. CVE-2017-11746[0]: | Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a | non-root