[Bug 1093661] Re: cgrulesengd fails to start

2013-01-09 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libcgroup in Ubuntu. https://bugs.launchpad.net/bugs/1093661 Title: cgrulesengd fails to start To manage notifications

[Bug 1097691] Re: (CVE-2012-5977) AST-2012-015 Denial of Service Through Exploitation of Device State Caching

2013-01-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1097687] Re: (CVE-2012-5976) AST-2012-014 Crashes due to large stack allocations when using TCP

2013-01-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1098299] [NEW] entropy pool should be seeded earlier in boot process

2013-01-10 Thread Marc Deslauriers
*** This bug is a security vulnerability *** Public security bug reported: Currently, the entropy pool is seeded by /etc/init.d/urandom. This should be done earlier in the boot process by an upstart job, and should be done before the ssh daemon is started. Although the ssh keys are generated on

[Bug 1100264] [NEW] mysql 5.5.29, 5.1.67 security update tracking bug

2013-01-16 Thread Marc Deslauriers
) Importance: Medium Assignee: Marc Deslauriers (mdeslaur) Status: In Progress ** Affects: mysql-dfsg-5.1 (Ubuntu) Importance: Undecided Status: Invalid ** Affects: mysql-5.1 (Ubuntu Lucid) Importance: Undecided Status: Invalid ** Affects: mysql-5.5 (Ubuntu

[Bug 1099793] Re: php 5.3.10 openssl_encrypt empty data

2013-01-18 Thread Marc Deslauriers
Introduced in 5.3.9 by: http://git.php.net/?p=php- src.git;a=commitdiff;h=095cbc48a8f0090f3b0abc6155f2b61943c9eafb Fixed in 5.3.14 by: http://git.php.net/?p=php- src.git;a=commitdiff;h=270a406ac94b5fc5cc9ef59fc61e3b4b95648a3e -- You received this bug notification because you are a member of

[Bug 1099793] Re: php 5.3.10 openssl_encrypt empty data

2013-01-18 Thread Marc Deslauriers
CVE requested: http://www.openwall.com/lists/oss-security/2013/01/18/5 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php5 in Ubuntu. https://bugs.launchpad.net/bugs/1099793 Title: php 5.3.10 openssl_encrypt empty data To manage

[Bug 1099793] Re: php 5.3.10 openssl_encrypt empty data

2013-01-18 Thread Marc Deslauriers
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2012-6113 ** Also affects: php5 (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: php5 (Ubuntu Quantal) Importance: Undecided Status: New ** Also affects: php5 (Ubuntu Raring) Importance:

[Bug 1099793] Re: php 5.3.10 openssl_encrypt empty data

2013-01-18 Thread Marc Deslauriers
** Changed in: php5 (Ubuntu Raring) Status: Confirmed = Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php5 in Ubuntu. https://bugs.launchpad.net/bugs/1099793 Title: php 5.3.10 openssl_encrypt empty data To

[Bug 1099793] Re: php 5.3.10 openssl_encrypt empty data

2013-01-18 Thread Marc Deslauriers
** Changed in: php5 (Ubuntu Precise) Assignee: (unassigned) = Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php5 in Ubuntu. https://bugs.launchpad.net/bugs/1099793 Title: php 5.3.10 openssl_encrypt

[Bug 1033727] Re: USB passthrough doesn't work anymore with qemu-kvm 1.1.1

2013-01-23 Thread Marc Deslauriers
This is likely fixed with the qemu version in raring. Unsubscribing ubuntu-sponsors. ** Also affects: qemu (Ubuntu) Importance: Undecided Status: New ** Also affects: qemu (Ubuntu Quantal) Importance: Undecided Status: New ** Also affects: qemu-kvm (Ubuntu Quantal)

[Bug 1061244] Re: Fix net rpc share allowedusers to work with 2008r2

2013-01-23 Thread Marc Deslauriers
Debdiff looks good. ACK. Uploaded to precise-proposed. Thanks! -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1061244 Title: Fix net rpc share allowedusers to work with 2008r2 To

[Blueprint servercloud-r-libvirt] Libvirt work for R

2013-01-31 Thread Marc Deslauriers
Blueprint changed by Marc Deslauriers: Work items changed: Work items: [serge-hallyn] Have virbr0 not be set to autostart if it's network is in use: DONE [stefan-bader-canonical] watch for libxl patches for xen 4.2: TODO - [mdeslaur] make sure OVMF support in virt-manager is sufficient

[Bug 1115053] Re: Parameter Handling Denial of Service in Oneiric

2013-02-05 Thread Marc Deslauriers
tomcat7 in oneiric is vulnerable to the following CVEs: CVE-2011-3375 CVE-2011-3376 CVE-2011-4858 CVE-2012-0022 CVE-2012-2733 CVE-2012-3546 CVE-2012-4431 CVE-2012-4534 CVE-2012-5568 CVE-2012-5885 CVE-2012-5886 CVE-2012-5887 See the CVE tracker for more information:

[Bug 1115053] Re: Parameter Handling Denial of Service in Oneiric

2013-02-06 Thread Marc Deslauriers
Unsubscribing ubuntu-security-sponsors for now, please re-subscribe when a new debdiff is available. Thanks! -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to tomcat7 in Ubuntu. https://bugs.launchpad.net/bugs/1115053 Title: Parameter

[Bug 1126488] Re: libvirt instance of dnsmasq in raring fails to forward DNS requests

2013-02-15 Thread Marc Deslauriers
I was waiting for 2.66 to come out. Simon, is a 2.66 release planned soon? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to dnsmasq in Ubuntu. https://bugs.launchpad.net/bugs/1126488 Title: libvirt instance of dnsmasq in raring

[Bug 1126488] Re: libvirt instance of dnsmasq in raring fails to forward DNS requests

2013-02-15 Thread Marc Deslauriers
This is the actual bug: https://bugzilla.redhat.com/show_bug.cgi?id=904940 ** Bug watch added: Red Hat Bugzilla #904940 https://bugzilla.redhat.com/show_bug.cgi?id=904940 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to dnsmasq in

[Bug 1117761] Re: SRU Tracking Bug for Postfix 2.9.6

2013-02-20 Thread Marc Deslauriers
I've successfully run the QRT test script on the versions in precise- proposed and quantal-proposed. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to postfix in Ubuntu. https://bugs.launchpad.net/bugs/1117761 Title: SRU Tracking Bug

[Bug 1121526] Re: False positives on trojans (Trojan.Agent-132354)

2013-02-22 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to clamav in Ubuntu. https://bugs.launchpad.net/bugs/1121526 Title: False positives on trojans (Trojan.Agent-132354) To manage

[Bug 1121439] Re: package bacula-director-mysql 5.2.5-0ubuntu6.2 failed to install/upgrade: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 1

2013-02-22 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1130616] Re: package freeradius 2.1.10+dfsg-3ubuntu0.12.04.1 failed to install/upgrade: podproces zainstalowany skrypt post-installation zwrócił kod błędu 1

2013-02-22 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1129029] Re: ACL not respected if an attachment file name contains the € character

2013-02-22 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to exim4 in Ubuntu. https://bugs.launchpad.net/bugs/1129029 Title: ACL not respected if an attachment file name contains the €

[Bug 1115053] Re: Multiple open vulnerabilities in tomcat7 in 12.04 and 11.10

2013-03-01 Thread Marc Deslauriers
Thanks for the updated debdiff. Unfortunately, I am also getting the following additional test suite failure: output/build/logs/TEST-org.apache.catalina.core.TestAsyncContextImpl.BIO.txt: Tests run: 32, Failures: 1, Errors: 0, Time elapsed: 75.853 sec This definitely needs to be tracked down

[Bug 1115053] Re: Multiple open vulnerabilities in tomcat7 in 12.04 and 11.10

2013-03-18 Thread Marc Deslauriers
Unsubscribing ubuntu-security-sponsors for now. Please resubscribe after a precise debdiff has been attached. Thanks! -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to tomcat7 in Ubuntu. https://bugs.launchpad.net/bugs/1115053 Title:

[Bug 1157385] [NEW] 0.97.7 security update

2013-03-19 Thread Marc Deslauriers
*** This bug is a security vulnerability *** Public security bug reported: This is the tracking bug for the 0.97.7 security update. ** Affects: clamav (Ubuntu) Importance: Undecided Assignee: Marc Deslauriers (mdeslaur) Status: Fix Released ** Affects: clamav (Ubuntu Lucid

[Bug 1157385] Re: 0.97.7 security update

2013-03-19 Thread Marc Deslauriers
) Assignee: (unassigned) = Marc Deslauriers (mdeslaur) ** Changed in: clamav (Ubuntu Oneiric) Assignee: (unassigned) = Marc Deslauriers (mdeslaur) ** Changed in: clamav (Ubuntu Precise) Assignee: (unassigned) = Marc Deslauriers (mdeslaur) ** Changed in: clamav (Ubuntu Quantal

[Bug 1161794] Re: CVE-2013-2266: A Maliciously Crafted Regular Expression Can Cause Memory Exhaustion in named

2013-03-29 Thread Marc Deslauriers
This is fixed now: http://www.ubuntu.com/usn/usn-1783-1/ ** Project changed: bind = bind9 (Ubuntu) ** Changed in: bind9 (Ubuntu) Status: New = Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to bind9 in Ubuntu.

[Bug 1163648] Re: package libservlet2.5-java (not installed) failed to install/upgrade: short read on buffer copy for backend dpkg-deb during `./usr/share/fonts/truetype/tlwg/Kinnari-BoldItalic.ttf'

2013-04-04 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1167394] Re: segfaults with php-fpm and current php5-memcached

2013-05-10 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php5 in Ubuntu. https://bugs.launchpad.net/bugs/1167394 Title: segfaults with php-fpm and current php5-memcached To manage

[Bug 1172909] Re: package clamav-milter 0.97.7+dfsg-1ubuntu0.12.04.1 failed to install/upgrade: installed post-installation script alfolyamat 1 hibakóddal kilépett

2013-05-10 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1178645] Re: tomcat7 needs update to 7.0.40

2013-05-10 Thread Marc Deslauriers
** Also affects: tomcat7 (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: tomcat7 (Ubuntu Quantal) Importance: Undecided Status: New ** Also affects: tomcat7 (Ubuntu Raring) Importance: Undecided Status: New ** Also affects: tomcat7 (Ubuntu

[Bug 1178645] Re: tomcat7 needs update to 7.0.40

2013-05-27 Thread Marc Deslauriers
Looks like packages.ubuntu.com is out of date: https://launchpad.net/ubuntu/+source/tomcat7/7.0.40-2 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to tomcat7 in Ubuntu. https://bugs.launchpad.net/bugs/1178645 Title: tomcat7 needs

[Bug 1184440] Re: package bind9 1:9.9.2.dfsg.P1-2ubuntu2 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2013-05-31 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1184223] Re: CVE-2013-2061: use of non-constant-time memcmp in HMAC comparison in openvpn_decrypt

2013-05-31 Thread Marc Deslauriers
** Also affects: openvpn (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: openvpn (Ubuntu Quantal) Importance: Undecided Status: New ** Also affects: openvpn (Ubuntu Saucy) Importance: Undecided Status: New ** Also affects: openvpn (Ubuntu

[Bug 1184223] Re: CVE-2013-2061: use of non-constant-time memcmp in HMAC comparison in openvpn_decrypt

2013-06-04 Thread Marc Deslauriers
Thanks for the merge request. We rate this security vulnerability as being low priority, which means we will not publish a security update for it unless another more important issue turns up in openvpn, at which point we will bundle both updates together. I am unsubscribing

[Bug 1020267] Re: [MIR] celery, pyparsing, python-cl, python-gevent, python-mailer, python-pytyrant, python-redis

2013-06-06 Thread Marc Deslauriers
For the maas SRU to precise in 1109283, these dependencies need to be promoted to main. This has an impact on security maintenance for precise. Since this removes the cobbler code copy from the maas package in precise, I am ok with the tradeoff. ACK from the security team for promoting the

[Bug 1188069] Re: apache2 mod_rewrite CVE 2013-1862

2013-06-06 Thread Marc Deslauriers
We are tracking this issue here: http://people.canonical.com/~ubuntu-security/cve/?cve=CVE-2013-1862 Since this issue has been rated as having a low priority, we will not be releasing a security update until more important issues are found, at which point the security update will bundle them.

[Bug 1173357] Re: Postfix in Lucid server vulnerable to CVE-2012-4929

2013-06-12 Thread Marc Deslauriers
We currently have openssl packages in -proposed which disable ssl compression by default. Please test them, and comment in bug #1187195 if they resolve your issue. Thanks. ** Information type changed from Private Security to Public Security ** Changed in: postfix (Ubuntu) Status: New =

[Bug 1188827] Re: User option (-u or --user) is ignored

2013-06-12 Thread Marc Deslauriers
The parent process never drops privileges, only the child process which is handling a connection drops privileges. You need to look at the privileges of the child during a connection. I am closing this bug. If you can demonstrate that the child process isn't dropping privileges, please feel free

[Bug 1192367] Re: No security release provided in Lucid for CVE-2013-3567

2013-06-19 Thread Marc Deslauriers
Thanks, we've fixed the date at the top of the file. That file is the authoritative list of packages supported by the security team, and contains the list the packages we deemed able to support for 5 years instead of the base 3 years. The puppet version in Lucid is ancient, is no longer

[Bug 1192367] Re: No security release provided in Lucid for CVE-2013-3567

2013-06-19 Thread Marc Deslauriers
I'll also investigate if we can get the puppet version from Precise into lucid-backports. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to puppet in Ubuntu. https://bugs.launchpad.net/bugs/1192367 Title: No security release provided

[Bug 1178826] Re: spamassassin broken error control on bad UNIX socket parameter

2013-06-19 Thread Marc Deslauriers
As commented in the merge request, since upstream fixed this in a different way, I don't think we should be carrying a distro patch just to get some more debugging information. NACK. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to

Re: [Bug 1192367] Re: No security release provided in Lucid for CVE-2013-3567

2013-06-20 Thread Marc Deslauriers
On 13-06-20 01:58 PM, Alex Vandiver wrote: On Wed, 2013-06-19 at 11:55 +, Marc Deslauriers wrote: That file is the authoritative list of packages supported by the security team, and contains the list the packages we deemed able to support for 5 years instead of the base 3 years

[Bug 1192367] Re: No security release provided in Lucid for CVE-2013-3567

2013-07-05 Thread Marc Deslauriers
Since there is no actionable item, I am marking this bug as Won't fix. Thanks. ** Information type changed from Public Security to Public ** Changed in: puppet (Ubuntu) Status: New = Won't Fix -- You received this bug notification because you are a member of Ubuntu Server Team, which is

[Bug 1197884] Re: apache2.2 SSL has no forward-secrecy: need ECDHE keys

2013-07-05 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: apache2 (Ubuntu) Status: New = Confirmed ** Changed in: apache2 (Ubuntu) Importance: Undecided = Wishlist -- You received this bug notification because you are a member of Ubuntu Server Team, which is

[Bug 843701] Re: CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure

2011-09-26 Thread Marc Deslauriers
Subscribing ubuntu-security-sponsors for the hardy tomcat5.5 update. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to tomcat6 in Ubuntu. https://bugs.launchpad.net/bugs/843701 Title: CVE-2011-3190 Apache Tomcat Authentication bypass

[Bug 843701] Re: CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure

2011-09-26 Thread Marc Deslauriers
Thanks for the branches. Tomcat6 updates have already been prepared by the security team, and are currently being tested. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to tomcat6 in Ubuntu. https://bugs.launchpad.net/bugs/843701 Title:

[Bug 843701] Re: CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure

2011-09-26 Thread Marc Deslauriers
Added tomcat5.5 task and re-subscribed ubuntu-security-sponsors since there's a tomcat5.5 branch linked here for sponsoring. ** Also affects: tomcat5.5 (Ubuntu) Importance: Undecided Status: New ** Changed in: tomcat5.5 (Ubuntu Lucid) Status: New = Invalid ** Changed in:

[Bug 868753] Re: qemu+ssh connections to a remote libvirt fail

2011-10-05 Thread Marc Deslauriers
Looks like a libvirt issue, reassigning. ** Package changed: virt-manager (Ubuntu) = libvirt (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in Ubuntu. https://bugs.launchpad.net/bugs/868753 Title: qemu+ssh

[Bug 769354] Re: elinks accepts self-signed ssl certificates without warning

2011-10-08 Thread Marc Deslauriers
** Changed in: elinks (Ubuntu) Assignee: 杨敏 (mandy9337) = (unassigned) ** Visibility changed to: Public -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to elinks in Ubuntu. https://bugs.launchpad.net/bugs/769354 Title: elinks

[Bug 852871] Re: PHP ZEND_SL Opcode Interruption Address Information Leak Vulnerability

2011-10-17 Thread Marc Deslauriers
** Also affects: php5 (Ubuntu Hardy) Importance: Undecided Status: New ** Also affects: php5 (Ubuntu Lucid) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php5 in Ubuntu.

[Bug 852865] Re: strrchr() functions information leak

2011-10-17 Thread Marc Deslauriers
** Also affects: php5 (Ubuntu Hardy) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php5 in Ubuntu. https://bugs.launchpad.net/bugs/852865 Title: strrchr() functions information leak To

[Bug 840386] Re: Update munin to bugfix release 1.4.6

2011-10-21 Thread Marc Deslauriers
1.4.6 is now in Precise. I'm closing this bug. ** Changed in: munin (Ubuntu) Status: Triaged = Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to munin in Ubuntu. https://bugs.launchpad.net/bugs/840386 Title:

[Bug 881361] Re: puppetmaster-passenger fails to install with puppet 2.6.4-2ubuntu2.5

2011-10-25 Thread Marc Deslauriers
This looks like it only affects Natty... ** Changed in: puppet (Ubuntu Lucid) Status: New = Invalid ** Changed in: puppet (Ubuntu Maverick) Status: New = Invalid ** Changed in: puppet (Ubuntu Oneiric) Status: New = Invalid ** Changed in: puppet (Ubuntu Precise)

[Bug 883813] Re: ubuntu 11.10 apache session

2011-11-06 Thread Marc Deslauriers
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability ** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability ** Package changed: ubuntu = php5 (Ubuntu) ** Summary changed: - ubuntu 11.10 apache session + php

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-06 Thread Marc Deslauriers
** Visibility changed to: Public ** Visibility changed to: Public ** Changed in: openldap (Ubuntu) Status: New = Confirmed ** Changed in: openldap (Ubuntu) Importance: Undecided = Medium -- You received this bug notification because you are a member of Ubuntu Server Team, which is

[Bug 885904] Re: CVE-2011-1148 Use-after-free vulnerability in the substr_replace function allows context-dependent attackers to cause a denial of service

2011-11-06 Thread Marc Deslauriers
This is fixed already, see: http://www.ubuntu.com/usn/usn-1126-1/ ** Visibility changed to: Public ** Visibility changed to: Public ** Changed in: php5 (Ubuntu) Status: New = Invalid -- You received this bug notification because you are a member of Ubuntu Server Team, which is

[Bug 885758] Re: 'ldap passwd sync = yes' and ldap password not updated

2011-11-06 Thread Marc Deslauriers
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability ** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed

[Bug 882507] Re: Sync puppet 2.7.6-1 (main) from Debian sid (main)

2011-11-14 Thread Marc Deslauriers
Synced: [ubuntu/precise] puppet 2.7.6-1 (Accepted) ** Changed in: puppet (Ubuntu) Status: Confirmed = Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to puppet in Ubuntu. https://bugs.launchpad.net/bugs/882507

[Bug 891389] Re: CVE-2011-4313 improper assert

2011-11-16 Thread Marc Deslauriers
This has been published now: http://www.ubuntu.com/usn/usn-1264-1/ ** Visibility changed to: Public ** Changed in: bind9 (Ubuntu) Status: Fix Committed = Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to bind9 in

[Bug 898363] Re: Command: echo package_name hold is not working

2011-12-01 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 900553] Re: Any user can manage the keystone database via keystone-manage

2011-12-06 Thread Marc Deslauriers
** This bug has been flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to keystone in Ubuntu. https://bugs.launchpad.net/bugs/900553 Title: Any user can manage the keystone database via keystone-manage

[Bug 905029] Re: unexpected end-of-file

2011-12-15 Thread Marc Deslauriers
You can download the previous version from this page: For i386: https://launchpad.net/~ubuntu-security/+archive/ppa/+build/2844451 For amd64: https://launchpad.net/~ubuntu-security/+archive/ppa/+build/289 Please indicate if downgrading has worked for you. ** Visibility changed to: Public

[Bug 909828] Re: Tomcat needs update to prevent hash function DoS attack

2012-01-06 Thread Marc Deslauriers
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2011-4858 ** Also affects: tomcat6 (Ubuntu Lucid) Importance: Undecided Status: New ** Also affects: tomcat6 (Ubuntu Maverick) Importance: Undecided Status: New ** Also affects: tomcat6 (Ubuntu Oneiric)

[Bug 910296] Re: Please backport the upstream patch to prevent attacks based on hash collisions

2012-01-06 Thread Marc Deslauriers
** Also affects: php5 (Ubuntu Lucid) Importance: Undecided Status: New ** Also affects: php5 (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: php5 (Ubuntu Maverick) Importance: Undecided Status: New ** Also affects: php5 (Ubuntu Hardy)

[Bug 914306] Re: sorry, the programparted_serverclosed unexpectedly

2012-01-11 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 907690] Re: CVE-2011-3205: DoS (memory corruption and daemon restart) or remote Gopher servers.

2012-01-16 Thread Marc Deslauriers
Thanks for the debdiffs. Sorry for the delay in reviewing them. ACK for maverick, natty and oneiric. They are being built now and will be released in a few hours. NACK for lucid. There seems to be a line missing in the CVE-2011-3205 patch. Could you please check, and attach a fixed debdiff?

[Bug 907690] Re: CVE-2011-3205: DoS (memory corruption and daemon restart) or remote Gopher servers.

2012-01-17 Thread Marc Deslauriers
Maverick-Oneiric have been released now, and will appear in mirrors in the next few hours. ** Changed in: squid3 (Ubuntu Maverick) Status: Fix Committed = Fix Released ** Changed in: squid3 (Ubuntu Natty) Status: Fix Committed = Fix Released ** Changed in: squid3 (Ubuntu Oneiric)

[Bug 907687] Re: CVE-2010-0639: DoS (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port

2012-01-17 Thread Marc Deslauriers
Only affects lucid. ** Changed in: squid3 (Ubuntu Maverick) Status: New = Invalid ** Changed in: squid3 (Ubuntu Natty) Status: New = Invalid ** Changed in: squid3 (Ubuntu Oneiric) Status: New = Invalid -- You received this bug notification because you are a member of

[Bug 915941] Re: overlayfs does not honor lxc-related permissions

2012-01-17 Thread Marc Deslauriers
** This bug has been flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/915941 Title: overlayfs does not honor lxc-related permissions To manage

[Bug 915941] Re: overlayfs does not honor lxc-related permissions

2012-01-17 Thread Marc Deslauriers
This is CVE-2012-0055 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2012-0055 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/915941 Title: overlayfs does not honor

[Bug 907690] Re: CVE-2011-3205: DoS (memory corruption and daemon restart) or remote Gopher servers.

2012-01-19 Thread Marc Deslauriers
debdiff looks good. ACK. I'm building the package now and will release it today. Thanks! ** Changed in: squid3 (Ubuntu Lucid) Status: New = Fix Committed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to squid3 in Ubuntu.

[Bug 921200] Re: tomcat 6.0.35 in Lucid

2012-01-27 Thread Marc Deslauriers
*** This bug is a duplicate of bug 909828 *** https://bugs.launchpad.net/bugs/909828 ** This bug has been marked a duplicate of bug 909828 Tomcat needs update to prevent hash function DoS attack -- You received this bug notification because you are a member of Ubuntu Server Team, which

[Bug 909828] Re: Tomcat needs update to prevent hash function DoS attack

2012-01-27 Thread Marc Deslauriers
There are now updated tomcat6 packages that fix this issue, and CVE-2012-0022 in -proposed. Since the patch is quite intrusive, they will stay in -proposed until they get some testing. If you would like to help, please enable -proposed, test the updates, and post your results here. Thanks. **

[Bug 916153]

2012-01-27 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 916153] Re: libcgroup1 security issues

2012-01-27 Thread Marc Deslauriers
** Changed in: libcgroup (Ubuntu) Status: New = Confirmed ** Changed in: libcgroup (Ubuntu) Importance: Undecided = Medium -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libcgroup in Ubuntu.

[Bug 925028] Re: apparmor breaks lxc-start-ephemeral (apparmor+overlayfs returns -EINVAL)

2012-02-06 Thread Marc Deslauriers
** Also affects: linux (Ubuntu Precise) Importance: Undecided Status: Confirmed ** Also affects: lxc (Ubuntu Precise) Importance: High Status: Confirmed ** Changed in: linux (Ubuntu Precise) Milestone: None = ubuntu-12.04-beta-1 ** Tags added: rls-p-tracking -- You

[Bug 909828] Re: Tomcat needs update to prevent hash function DoS attack

2012-02-07 Thread Marc Deslauriers
SRU team: This is a security update. If the packages have the required testing to publish, please let the security team know so we can publish the USN and push it to -security also. Thanks! -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed

[Bug 811422] Re: Exploitable integer overflow on x86 in mod SetEnvIf, leading to buffer overwrite

2012-02-14 Thread Marc Deslauriers
: New = Confirmed ** Changed in: apache2 (Ubuntu Precise) Status: Incomplete = Fix Released ** Changed in: apache2 (Ubuntu Precise) Assignee: Jamie Strandboge (jdstrand) = (unassigned) ** Changed in: apache2 (Ubuntu Hardy) Assignee: (unassigned) = Marc Deslauriers (mdeslaur

[Bug 931859] Re: chown: cannot access `/etc/nagios3/resource.cfg': No such file or directory

2012-02-15 Thread Marc Deslauriers
Thanks for the debdiff. Seems to me removing all the permission setting in the postinst is the wrong way to fix this. How are those permissions going to get setup? How about doing something like this instead? test -f $en/resource.cfg setperm root nagios 0640 $en/resource.cfg NACK on the

[Bug 931859] Re: chown: cannot access `/etc/nagios3/resource.cfg': No such file or directory

2012-02-15 Thread Marc Deslauriers
Ah! that makes sense. Thanks for the new information. ACK on the debdiff. The only change I will do before uploading is changing the version to 3.2.3-3ubuntu1 since we now have a Ubuntu delta. ** Changed in: nagios3 (Ubuntu) Status: Confirmed = Fix Committed -- You received this bug

[Bug 937869] [NEW] 5.1.x security update tracking bug

2012-02-21 Thread Marc Deslauriers
-5.1 (Ubuntu Lucid) Importance: Undecided Status: Invalid ** Affects: mysql-dfsg-5.1 (Ubuntu Lucid) Importance: Undecided Assignee: Marc Deslauriers (mdeslaur) Status: Confirmed ** Affects: mysql-5.1 (Ubuntu Maverick) Importance: Undecided Assignee: Marc

[Bug 937869] Re: MySQL security update tracking bug

2012-02-23 Thread Marc Deslauriers
** Changed in: mysql-dfsg-5.0 (Ubuntu Hardy) Status: New = Confirmed ** Changed in: mysql-dfsg-5.0 (Ubuntu Hardy) Assignee: (unassigned) = Marc Deslauriers (mdeslaur) ** Changed in: mysql-dfsg-5.0 (Ubuntu Lucid) Status: New = Invalid ** Changed in: mysql-dfsg-5.0 (Ubuntu Maverick

[Bug 937869] Re: MySQL security update tracking bug

2012-03-13 Thread Marc Deslauriers
** Changed in: mysql-dfsg-5.1 (Ubuntu) Status: In Progress = Fix Released ** Changed in: mysql-dfsg-5.0 (Ubuntu) Status: In Progress = Fix Released ** Changed in: mysql-5.1 (Ubuntu) Status: In Progress = Fix Released -- You received this bug notification because you are a

[Bug 954759] Re: php5 10.04 LTS critical bug fixes

2012-03-14 Thread Marc Deslauriers
Ubuntu backports security fixes into stable releases. The php version in Lucid gets all security fixes. Here are the latest ones: http://www.ubuntu.com/usn/usn-1358-1/ See our FAQ: https://wiki.ubuntu.com/SecurityTeam/FAQ#Versions ** Visibility changed to: Public ** Changed in: php5 (Ubuntu)

[Bug 578536] Re: when stopped, automount orphans some mounts

2012-03-14 Thread Marc Deslauriers
Chris, A couple of comments on your debdiff: 1- Could you change the version to 5.0.5-0ubuntu6.1 2- Could you add some tags to your patch to explain it's provenance (See http://dep.debian.net/deps/dep3/) Thanks. -- You received this bug notification because you are a member of Ubuntu Server

[Bug 965523] [NEW] mysql 5.5.22, 5.1.62, 5.0.96 security update tracking bug

2012-03-26 Thread Marc Deslauriers
: Undecided Assignee: Marc Deslauriers (mdeslaur) Status: Confirmed ** Affects: mysql-5.1 (Ubuntu Maverick) Importance: Undecided Assignee: Marc Deslauriers (mdeslaur) Status: Confirmed ** Affects: mysql-5.5 (Ubuntu Maverick) Importance: Undecided Status

[Bug 958831] Re: Samba rebroadcasts information it should not

2012-04-06 Thread Marc Deslauriers
This is how the smb protocol browsing is designed to function. If you don't want your workstation to act as a master browser, you need to turn off the options in smb.conf. Maybe something like this? [global] domain master = no local master = no preferred master = no os level = 0 ** Visibility

[Bug 972603] Re: package amavisd-new-postfix 1:2.6.5-0ubuntu3 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2012-04-06 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 974460] Re: cobbler-ubuntu-import does not check gpg signatures

2012-04-10 Thread Marc Deslauriers
** Visibility changed to: Public -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to cobbler in Ubuntu. https://bugs.launchpad.net/bugs/974460 Title: cobbler-ubuntu-import does not check gpg signatures To manage notifications about

[Bug 974460] Re: cobbler-ubuntu-import does not check gpg signatures

2012-04-10 Thread Marc Deslauriers
CVE requested: http://www.openwall.com/lists/oss-security/2012/04/10/8 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to cobbler in Ubuntu. https://bugs.launchpad.net/bugs/974460 Title: cobbler-ubuntu-import does not check gpg

[Bug 974460] Re: cobbler-ubuntu-import does not check gpg signatures

2012-04-10 Thread Marc Deslauriers
This is CVE-2012-2092 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2012-2092 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to cobbler in Ubuntu. https://bugs.launchpad.net/bugs/974460 Title: cobbler-ubuntu-import

[Bug 978708] Re: [Precise] puppet is vulnerable to CVE-2012-1906 and CVE-2012-1986 through CVE-2012-1989

2012-04-11 Thread Marc Deslauriers
ACK on the debdiff, uploaded to Precise. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to puppet in Ubuntu. https://bugs.launchpad.net/bugs/978708 Title: [Precise] puppet is vulnerable to CVE-2012-1906 and CVE-2012-1986 through

[Bug 980758] Re: new buffer overflow attack on samba 3.6.3 - enables unauthenticated remote root access

2012-04-13 Thread Marc Deslauriers
*** This bug is a duplicate of bug 978458 *** https://bugs.launchpad.net/bugs/978458 ** This bug has been marked a duplicate of bug 978458 CVE-2012-1182: root credential remote code execution -- You received this bug notification because you are a member of Ubuntu Server Team, which is

[Bug 988325] Re: mysql-server should not stop mysql service

2012-04-27 Thread Marc Deslauriers
** Changed in: mysql-dfsg-5.0 (Ubuntu) Assignee: (unassigned) = Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to mysql-dfsg-5.0 in Ubuntu. https://bugs.launchpad.net/bugs/988325 Title: mysql-server

[Bug 994169] [NEW] quagga security update tracking bug

2012-05-03 Thread Marc Deslauriers
Four-octet AS Number Capability - CVE-2012-0249 - CVE-2012-0250 - CVE-2012-0255 ** Affects: quagga (Ubuntu) Importance: Medium Status: Fix Released ** Affects: quagga (Ubuntu Lucid) Importance: Medium Assignee: Marc Deslauriers (mdeslaur) Status

[Bug 993657] Re: package samba 2:3.6.3-2ubuntu2.1 failed to install/upgrade: subproses skrip post-installation terpasang menghasilkan kesalahan status keluaran: 1

2012-05-04 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 996162]

2012-05-14 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 999082] Re: package puppetmaster 0.25.4-2ubuntu6.7 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2012-05-14 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 998520] Re: package amavisd-new-postfix 1:2.6.5-0ubuntu3 failed to install/upgrade: il sottoprocesso vecchio script di post-installation ha restituito lo stato di errore 1

2012-05-14 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

  1   2   3   4   5   6   7   8   9   10   >