Bug#552433: Fwd: Bug#552433: libnss-ldapd: ignores case of uids

2009-11-22 Thread Arthur de Jong
On Thu, 2009-11-05 at 21:07 +0100, Arthur de Jong wrote: I will contact the security team and prepare an update. I am awaiting a response from the security team whether to do this via a security update or via proposed-updates. An updated 0.6.7.2 package is being prepared here:

Bug#552433: Fwd: Bug#552433: libnss-ldapd: ignores case of uids

2009-11-05 Thread Petter Reinholdtsen
[Arthur de Jong] Thanks for pointing this out and providing the link. I will contact the security team and prepare an update. Great. :) It is strange though that the group membership is lost because I would think those lookups would also be case-insensitive. I noticed the case-insensitive

Bug#552433: Fwd: Bug#552433: libnss-ldapd: ignores case of uids

2009-11-05 Thread Arthur de Jong
On Thu, 2009-11-05 at 17:32 +0100, Petter Reinholdtsen wrote: I really hope you find time to fix this in Lenny, as it affects Debian Edu. The issue is also a security issue, where users can by-pass netgroup based limitations by changing the case of the username they use when logging in. See

Bug#552433: Fwd: Bug#552433: libnss-ldapd: ignores case of uids

2009-10-29 Thread Arthur de Jong
Dear stable release team, A user reported a bug (#552433) against libnss-ldapd which causes some problems and asked if a fix can be made available in a stable update. I can probably backport the fix to version 0.6.7.1 but I wanted to know if such a fix will be considered a candidate for