[Bug 834121] [NEW] CVE-2011-2918

2011-08-25 Thread Kees Cook
*** This bug is a security vulnerability *** Public security bug reported: Under certain circumstances software event overflows go wrong and deadlock. Avoid trying to delete a timer from the timer callback. Break-Fix: - a8b0ca17b80e92faab46ee7179ba9e99ccb61233 ** Affects: linux (Ubuntu)

[Bug 834121] Re: CVE-2011-2918

2011-08-25 Thread Kees Cook
CVE-2011-2918 ** Also affects: linux (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-lts-backport-maverick (Ubuntu Oneiric) Importance: Undecided Status:

[Bug 834129] [NEW] CVE-2011-3188

2011-08-25 Thread Kees Cook
*** This bug is a security vulnerability *** Public security bug reported: Dan Kaminsky pointed out that using partial MD4 and using that to generate a sequence number, of which only 24-bits are truly unguessable, seriously undermine the goals of random sequence number generation. ** Affects:

[Bug 834129] Re: CVE-2011-3188

2011-08-25 Thread Kees Cook
CVE-2011-3188 ** Also affects: linux (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-lts-backport-maverick (Ubuntu Oneiric) Importance: Undecided Status:

[Bug 834135] [NEW] CVE-2011-3191

2011-08-25 Thread Kees Cook
*** This bug is a security vulnerability *** Public security bug reported: cifs: singedness issue in CIFSFindNext() ** Affects: linux (Ubuntu) Importance: Medium Status: New ** Affects: linux-ec2 (Ubuntu) Importance: Medium Status: Invalid ** Affects:

[Bug 834135] Re: CVE-2011-3191

2011-08-25 Thread Kees Cook
CVE-2011-3191 ** Also affects: linux (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-lts-backport-maverick (Ubuntu Oneiric) Importance: Undecided Status:

[Bug 801299] Re: [MIR]glance

2011-08-25 Thread Kees Cook
It seems like running this over an open network without SSL would result in all of man-in-the-middle potential, credential theft, image changing, etc. Is there something I'm missing about this? It seems like a rather critical service to run without SSL. -- You received this bug notification

[Bug 823185] Re: [MIR] colord

2011-08-24 Thread Kees Cook
Thanks, looks good! ** Changed in: colord (Ubuntu) Status: Confirmed = Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/823185 Title: [MIR] colord To manage notifications about

[Bug 795159] Re: [MIR] ajaxterm

2011-08-18 Thread Kees Cook
Patch looks good, thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/795159 Title: [MIR] ajaxterm To manage notifications about this bug go to:

[Bug 795159] Re: [MIR] ajaxterm

2011-08-18 Thread Kees Cook
With these changes, I'm okay with the MIR. +1 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/795159 Title: [MIR] ajaxterm To manage notifications about this bug go to:

[Bug 804225] Re: CVE-2011-1010

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 768448] Re: CVE-2011-0712

2011-08-16 Thread Kees Cook
** Changed in: linux (Ubuntu Dapper) Status: Won't Fix = Invalid ** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low **

[Bug 823185] Re: [MIR] colord

2011-08-16 Thread Kees Cook
Thanks for the reply! The way I look at this is from the perspective of risk. There are two scenarios for crossing privilege boundaries: - the local user attacking colord via malicious DBus calls (to gain colord privs) - an external user attacking colord via inserted media (to gain colord

[Bug 804366] Re: CVE-2011-1019

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided =

[Bug 816542] Re: CVE-2011-1078

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 813026] Re: CVE-2011-1020

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 816544] Re: CVE-2011-1079

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 816545] Re: CVE-2011-1080

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 813935] Re: CVE-2011-1083

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 820029] Re: CVE-2011-1082

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 800775] Re: CVE-2011-1090

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 816546] Re: CVE-2011-1160

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 814087] Re: CVE-2011-1093

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided =

[Bug 801482] Re: CVE-2011-1171

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 796606] Re: CVE-2011-1163

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 801480] Re: CVE-2011-1170

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 823185] Re: [MIR] colord

2011-08-16 Thread Kees Cook
They seem like good ideas, but I haven't reviewed them yet. Does the --enable-fd-fallback patch mean that files are not opened by colord (i.e. they must be opened by the user first)? That would be an improvement for sure, though DoSing the daemon is still possible, but that's a much lower risk,

[Bug 801483] Re: CVE-2011-1172

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 801484] Re: CVE-2011-1173

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 816547] Re: CVE-2011-1180

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 795418] Re: CVE-2011-1577

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided =

[Bug 816550] Re: CVE-2011-1493

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 816549] Re: CVE-2011-1478

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 796502] Re: CVE-2011-1598

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 792312] Re: CVE-2011-1581

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided =

[Bug 791918] Re: CVE-2011-1746

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 788694] Re: CVE-2011-1748

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 806390] Re: CVE-2011-2484

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided =

[Bug 788684] Re: CVE-2011-2022

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided =

[Bug 732628] Re: TOCTOU in mount.ecryptfs_private

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Committed ** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low **

[Bug 819574] Re: CVE-2011-2695

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 819572] Re: CVE-2011-2689

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 788700] Re: CVE-2011-1747

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 806375] Re: CVE-2011-1770

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Medium ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided =

[Bug 819570] Re: CVE-2011-2534

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 806929] Re: CVE-2011-2493

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 819569] Re: CVE-2011-2492

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low **

[Bug 827685] Re: CVE-2011-2699

2011-08-16 Thread Kees Cook
CVE-2011-2699 ** Also affects: linux (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-lts-backport-maverick (Ubuntu Oneiric) Importance: Undecided Status:

[Bug 706999] Re: CVE-2010-3448

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Hardy) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Maverick) Importance: Undecided = Low ** Changed in: linux-ec2 (Ubuntu Natty) Importance: Undecided = Low **

[Bug 827685] Re: CVE-2011-2699

2011-08-16 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Natty) Status: New = Invalid ** Changed in: linux-lts-backport-natty (Ubuntu Oneiric) Status: New = Invalid

[Bug 827685] [NEW] CVE-2011-2699

2011-08-16 Thread Kees Cook
*** This bug is a security vulnerability *** Public security bug reported: Placeholder ** Affects: linux (Ubuntu) Importance: Undecided Status: New ** Affects: linux-fsl-imx51 (Ubuntu) Importance: Undecided Status: New ** Affects: linux-lts-backport-maverick

[Bug 817133] Re: [FFe] [needspackaging] ubuntuone-installer needs packaged

2011-08-15 Thread Kees Cook
@scottk hm? this is for oneiric, not an SRU, afaiu. ** Changed in: ubuntu Status: Incomplete = New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/817133 Title: [FFe] [needspackaging]

[Bug 823912] Re: linux: 2.6.24-29.93 -proposed tracker

2011-08-12 Thread Kees Cook
** Changed in: kernel-sru-workflow/security-signoff Status: Confirmed = In Progress ** Changed in: kernel-sru-workflow/security-signoff Assignee: Canonical Security Team (canonical-security) = Kees Cook (kees) -- You received this bug notification because you are a member of Ubuntu

[Bug 800853] Re: [MIR] heimdal

2011-08-12 Thread Kees Cook
Given it's long history, multi-arch support, etc, this all looks good to me. This is a pretty stable package. +1 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/800853 Title: [MIR] heimdal To manage

[Bug 800853] Re: [MIR] heimdal

2011-08-12 Thread Kees Cook
** Changed in: heimdal (Ubuntu) Status: Confirmed = In Progress ** Changed in: heimdal (Ubuntu) Assignee: Kees Cook (kees) = (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs

[Bug 819903] Re: [MIR] swift

2011-08-12 Thread Kees Cook
= In Progress ** Changed in: swift (Ubuntu) Assignee: Kees Cook (kees) = (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/819903 Title: [MIR] swift To manage notifications about

[Bug 823912] Re: linux: 2.6.24-29.93 -proposed tracker

2011-08-12 Thread Kees Cook
Looks good, thanks! ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress = Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/823912 Title: linux: 2.6.24-29.93

[Bug 823185] Re: [MIR] colord

2011-08-12 Thread Kees Cook
) Status: Confirmed = Incomplete ** Changed in: colord (Ubuntu) Assignee: Kees Cook (kees) = (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/823185 Title: [MIR] colord To manage

[Bug 811338] Re: [MIR] tokyotyrant

2011-08-12 Thread Kees Cook
) Status: New = In Progress ** Changed in: tokyotyrant (Ubuntu) Assignee: Kees Cook (kees) = (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/811338 Title: [MIR] tokyotyrant To manage

[Bug 818175] Re: linux: 2.6.38-11.48 -proposed tracker

2011-08-11 Thread Kees Cook
This looks good, thanks. ** Changed in: kernel-sru-workflow/security-signoff Status: In Progress = Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/818175 Title: linux:

[Bug 808765] Re: [MIR] liboauth

2011-08-11 Thread Kees Cook
This looks good, thanks. +1 ** Changed in: liboauth (Ubuntu) Status: New = In Progress ** Changed in: liboauth (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) = (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 824681] [NEW] Sync apparmor 2.7.0~beta1+bzr1774-1 (main) from Debian unstable (main)

2011-08-11 Thread Kees Cook
-lp810270.patch, taken upstream. - drop 0107-lp767308.patch, taken upstream. - drop 0108-gnome-mimeinfo.patch, taken upstream. - drop 0109-add-profile-repo-info.patch, taken upstream. * Add af_names-generation.patch to allow arbitrary socket.h file location. -- Kees Cook k...@debian.org

[Bug 817133] Re: [needspackaging] ubuntuone-installer needs packaged

2011-08-11 Thread Kees Cook
This doesn't look like it's ready for the archive to me: def __get_series(self): Get the series we're running on. return 'natty' That won't work for oneiric :) GUI strings aren't localized from what I can tell, so it would be English-only. Beyond that, it seems fine. It's

[Bug 801299] Re: [MIR]glance

2011-08-11 Thread Kees Cook
= Incomplete ** Changed in: glance (Ubuntu) Assignee: Kees Cook (kees) = (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/801299 Title: [MIR]glance To manage notifications about this bug go

[Bug 817995] Re: [MIR] p11-kit

2011-08-11 Thread Kees Cook
This looks good. Thanks for getting the symbols file in place. :) +1 ** Changed in: p11-kit (Ubuntu) Status: New = In Progress ** Changed in: p11-kit (Ubuntu) Assignee: Kees Cook (kees) = (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs

[Bug 822967] Re: 2.6.24-29.92-xen: failure on QRT 'ASLR of mmap'

2011-08-10 Thread Kees Cook
This was a false positive due to bad luck (it's a statistical test). I have adjusted the expected entropy a bit more so this failure should be much more rare now. ** Changed in: linux (Ubuntu) Status: New = Fix Released ** Changed in: linux (Ubuntu) Assignee: (unassigned) = Kees Cook

[Bug 812360] Re: linux: 2.6.24-29.92 -proposed tracker

2011-08-10 Thread Kees Cook
There were false positives and have been fixed now. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/812360 Title: linux: 2.6.24-29.92 -proposed tracker To manage notifications about this bug go to:

[Bug 732628] Re: TOCTOU in mount.ecryptfs_private

2011-08-10 Thread Kees Cook
** Also affects: ecryptfs-utils (Ubuntu Hardy) Importance: Undecided Status: New ** Also affects: linux-source-2.6.15 (Ubuntu Hardy) Importance: Undecided Status: New ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu

[Bug 732628] Re: TOCTOU in mount.ecryptfs_private

2011-08-10 Thread Kees Cook
** Changed in: linux-ti-omap (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-source-2.6.15 (Ubuntu Lucid) Status: New = Invalid ** Changed in: linux-source-2.6.15 (Ubuntu Maverick) Status: New = Invalid ** Changed in: linux-source-2.6.15 (Ubuntu Natty)

[Bug 804225] Re: CVE-2011-1010

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 804366] Re: CVE-2011-1019

2011-08-10 Thread Kees Cook
** Also affects: linux-ti-omap4 (Ubuntu Maverick) Importance: Undecided Status: New ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid ** Changed in: linux-lts-backport-natty (Ubuntu Maverick) Status: New = Invalid ** Changed in: linux-mvl-dove (Ubuntu

[Bug 804366] Re: CVE-2011-1019

2011-08-10 Thread Kees Cook
** Also affects: linux (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-ec2 (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-fsl-imx51 (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: linux-linaro

[Bug 706999] Re: CVE-2010-3448

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Natty) Status: New = Invalid ** Changed

[Bug 706999] Re: CVE-2010-3448

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Dapper) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Karmic) Status: New = Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706999

[Bug 813026] Re: CVE-2011-1020

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Committed ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 768448] Re: CVE-2011-0712

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Natty) Status: New = Invalid ** Changed

[Bug 816542] Re: CVE-2011-1078

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Committed ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 768448] Re: CVE-2011-0712

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Dapper) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Karmic) Status: New = Invalid ** Also affects: linux (Ubuntu Oneiric) Importance: Undecided Status: Fix Released ** Also affects: linux-ec2 (Ubuntu Oneiric) Importance:

[Bug 706999] Re: CVE-2010-3448

2011-08-10 Thread Kees Cook
** Changed in: linux-lts-backport-natty (Ubuntu Dapper) Status: New = Invalid ** Changed in: linux-lts-backport-natty (Ubuntu Karmic) Status: New = Invalid ** Changed in: linux-mvl-dove (Ubuntu Dapper) Status: New = Invalid ** Changed in: linux-mvl-dove (Ubuntu Karmic)

[Bug 816545] Re: CVE-2011-1080

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Committed ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 816544] Re: CVE-2011-1079

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Committed ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 820029] Re: CVE-2011-1082

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 813935] Re: CVE-2011-1083

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Natty) Status: New = Invalid -- You

[Bug 816546] Re: CVE-2011-1160

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Committed ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 814087] Re: CVE-2011-1093

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 801482] Re: CVE-2011-1171

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 801480] Re: CVE-2011-1170

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 800775] Re: CVE-2011-1090

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 796606] Re: CVE-2011-1163

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 801483] Re: CVE-2011-1172

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 816549] Re: CVE-2011-1478

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Committed ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 816547] Re: CVE-2011-1180

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Committed ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 801484] Re: CVE-2011-1173

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 816550] Re: CVE-2011-1493

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Committed ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 796502] Re: CVE-2011-1598

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 795418] Re: CVE-2011-1577

2011-08-10 Thread Kees Cook
** Description changed: Heap-based buffer overflow in the is_gpt_valid function in fs/partitions/efi.c in the Linux kernel 2.6.38 and earlier allows physically proximate attackers to cause a denial of service (OOPS) or possibly have unspecified other impact via a crafted size of the EFI

[Bug 792312] Re: CVE-2011-1581

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid ** Changed

[Bug 791918] Re: CVE-2011-1746

2011-08-10 Thread Kees Cook
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New = Fix Released ** Changed in: linux-ec2 (Ubuntu Oneiric) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Hardy) Status: New = Invalid ** Changed in: linux-ec2 (Ubuntu Maverick) Status: New = Invalid **

[Bug 768448] Re: CVE-2011-0712

2011-08-10 Thread Kees Cook
** Changed in: linux (Ubuntu Dapper) Status: Invalid = Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/768448 Title: CVE-2011-0712 To manage notifications about this bug go to:

[Bug 806375] Re: CVE-2011-1770

2011-08-10 Thread Kees Cook
** Description changed: Integer underflow in the dccp_parse_options function (net/dccp/options.c) in the Linux kernel before 2.6.33.14 allows remote attackers to cause a denial of service via a Datagram Congestion Control Protocol (DCCP) packet with an invalid feature options length,

<    1   2   3   4   5   6   7   8   9   10   >