Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Moritz Muehlenhoff
On Tue, Dec 08, 2009 at 01:42:23AM +0100, Manuel Prinz wrote: Here's the debdiff. Changes are checked into our SVN repo. Best regards Manuel You should rather use the copy of libltdl currently in the archive or is there a technical reason, which prevents this? Cheers, Moritz --

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Manuel Prinz
Hi Michael! Am Montag, den 07.12.2009, 00:06 -0500 schrieb Michael Gilbert: The following CVE (Common Vulnerabilities Exposures) id was published for libtool. I have determined that this package embeds a vulnerable copy of the libtool source code. However, since this is a mass bug filing

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Manuel Prinz
Here's the debdiff. Changes are checked into our SVN repo. Best regards Manuel diff -u openmpi-1.3.3/debian/changelog openmpi-1.3.3/debian/changelog --- openmpi-1.3.3/debian/changelog +++ openmpi-1.3.3/debian/changelog @@ -1,3 +1,10 @@ +openmpi (1.3.3-4) unstable; urgency=medium + + * Fixed

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Luk Claes
Manuel Prinz wrote: Hi Michael! Am Montag, den 07.12.2009, 00:06 -0500 schrieb Michael Gilbert: The following CVE (Common Vulnerabilities Exposures) id was published for libtool. I have determined that this package embeds a vulnerable copy of the libtool source code. However, since this