Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-19 Thread Jan Minar
On Sat, Apr 17, 2004 at 06:10:36PM -0400, Michael Stone wrote: The big problem is that the kernel situation in woody blows. There are too many kernels and they don't build consistently. Hopefully things will be better in sarge (although if you look at the number of kernels out there the future

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-19 Thread Matt Zimmerman
On Mon, Apr 19, 2004 at 06:40:35PM +0200, Jan Minar wrote: Could You tell us what _exactly_ happened? (DWN cover-story ;-)) Are there no testsuites/scripts to ensure basic sanity of the packages being built packages? Or what _exactly_ was the mistake (I'm personally interested in the

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-19 Thread Jan Minar
On Sat, Apr 17, 2004 at 06:10:36PM -0400, Michael Stone wrote: The big problem is that the kernel situation in woody blows. There are too many kernels and they don't build consistently. Hopefully things will be better in sarge (although if you look at the number of kernels out there the future

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-19 Thread Matt Zimmerman
On Mon, Apr 19, 2004 at 06:40:35PM +0200, Jan Minar wrote: Could You tell us what _exactly_ happened? (DWN cover-story ;-)) Are there no testsuites/scripts to ensure basic sanity of the packages being built packages? Or what _exactly_ was the mistake (I'm personally interested in the

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-17 Thread Michael Stone
On Thu, Apr 15, 2004 at 03:30:58PM +0700, Jean Christophe ANDRÉ wrote: When you have time, could you please tell people how could that happen? It's a mistake, it happens. Mike Stone -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-17 Thread Jean Christophe ANDRÉ
Le samedi 17 avril 2004 10h01 (-0400), Michael Stone crivait : When you have time, could you please tell people how could that happen? It's a mistake, it happens. Off course! And I don't ask to blame anybody! I'm just curious to know the details, so it may be usefull to me too when I'm

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-17 Thread Michael Stone
The big problem is that the kernel situation in woody blows. There are too many kernels and they don't build consistently. Hopefully things will be better in sarge (although if you look at the number of kernels out there the future seems grim) but woody will always have slow painful kernel

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-17 Thread Michael Stone
On Thu, Apr 15, 2004 at 03:30:58PM +0700, Jean Christophe ANDRÉ wrote: When you have time, could you please tell people how could that happen? It's a mistake, it happens. Mike Stone

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-17 Thread Jean Christophe ANDRÉ
Le samedi 17 avril 2004 à 10h01 (-0400), Michael Stone écrivait : When you have time, could you please tell people how could that happen? It's a mistake, it happens. Off course! And I don't ask to blame anybody! I'm just curious to know the details, so it may be usefull to me too when I'm

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-17 Thread Michael Stone
The big problem is that the kernel situation in woody blows. There are too many kernels and they don't build consistently. Hopefully things will be better in sarge (although if you look at the number of kernels out there the future seems grim) but woody will always have slow painful kernel

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-15 Thread Jean Christophe ANDRÉ
Hi Guys! Le mercredi 14 avril 2004 23h58 (+0200), Martin Schulze crivait : An unfortunate build error caused some of the kernel packages in DSA 479-1 to be broken. When you have time, could you please tell people how could that happen? Doesn't packaging process has any check for

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-15 Thread Jean Christophe ANDRÉ
Hi Guys! Le mercredi 14 avril 2004 à 23h58 (+0200), Martin Schulze écrivait : An unfortunate build error caused some of the kernel packages in DSA 479-1 to be broken. When you have time, could you please tell people how could that happen? Doesn't packaging process has any check for

Re: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386)

2004-04-14 Thread Lior Kaplan
Announcements debian-security-announce@lists.debian.org Sent: Wednesday, April 14, 2004 11:58 PM Subject: [SECURITY] [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386) -BEGIN PGP SIGNED MESSAGE- Hash: SHA1