[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#328395: marked as done (CAN-2005-2801: ext2 ext3 xattr access control bypass)



Your message dated Fri, 14 Oct 2005 13:22:41 +0900
with message-id <20051014042241.GD12050@verge.net.au>
and subject line CAN-2005-2801
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 15 Sep 2005 03:05:44 +0000
>From geoff.crompton@strategicdata.com.au Wed Sep 14 20:05:44 2005
Return-path: <geoff.crompton@strategicdata.com.au>
Received: from 203-214-67-82.dyn.iinet.net.au (sdcarl02.strategicdata.com.au) [203.214.67.82] 
	by spohr.debian.org with esmtp (Exim 3.36 1 (Debian))
	id 1EFk4G-0007gK-00; Wed, 14 Sep 2005 20:05:44 -0700
Received: from sd01 (localhost [127.0.0.1])
	by mail-int.strategicdata.com.au (Postfix) with ESMTP id C2B42C0042BB
	for <submit@bugs.debian.org>; Thu, 15 Sep 2005 13:05:42 +1000 (EST)
Received: 
	from sdcarl02.strategicdata.com.au (localhost [])
	by localhost ([127.0.0.1]);
	Thu, 15 Sep 2005 03:05:42 +0000
Received: from carthanach.mel.strategicdata.com.au (carthanach.mel.strategicdata.com.au [192.168.1.64])
	by sdcarl02.strategicdata.com.au (Postfix) with ESMTP id 22367C0042BB
	for <submit@bugs.debian.org>; Thu, 15 Sep 2005 13:05:42 +1000 (EST)
Received: by carthanach.mel.strategicdata.com.au (Postfix, from userid 1188)
	id C32CC4C4088; Thu, 15 Sep 2005 13:05:41 +1000 (EST)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Geoff Crompton <geoff.crompton@strategicdata.com.au>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CAN-2005-2801: ext2 ext3 xattr access control bypass
X-Mailer: reportbug 3.8
Date: Thu, 15 Sep 2005 13:05:41 +1000
Message-Id: <20050915030541.C32CC4C4088@carthanach.mel.strategicdata.com.au>
Delivered-To: submit@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level: 
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
	autolearn=no version=2.60-bugs.debian.org_2005_01_02

Package: linux-2.6
Severity: important

Ref http://www.securityfocus.com/bid/14793

The kernel team is aware of this issue, and fixes are in the kernel
teams svn at svn.debian.org.

I created this report so as I couldn't find this issue mentioned in the
BTS. Please tag it with security and sarge.

---------------------------------------
Received: (at 328395-done) by bugs.debian.org; 14 Oct 2005 04:40:42 +0000
>From horms@koto.vergenet.net Thu Oct 13 21:40:42 2005
Return-path: <horms@koto.vergenet.net>
Received: from koto.vergenet.net [210.128.90.7] 
	by spohr.debian.org with esmtp (Exim 3.36 1 (Debian))
	id 1EQHN3-0008B5-00; Thu, 13 Oct 2005 21:40:41 -0700
Received: by koto.vergenet.net (Postfix, from userid 7100)
	id F11EF3405E; Fri, 14 Oct 2005 13:39:41 +0900 (JST)
Date: Fri, 14 Oct 2005 13:22:41 +0900
From: Horms <horms@debian.org>
Cc: 328395-done@bugs.debian.org
Subject: CAN-2005-2801
Message-ID: <20051014042241.GD12050@verge.net.au>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
X-Cluestick: seven
User-Agent: Mutt/1.5.11
Delivered-To: 328395-done@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level: 
X-Spam-Status: No, hits=-3.0 required=4.0 tests=BAYES_00 autolearn=no 
	version=2.60-bugs.debian.org_2005_01_02

This bug is not present in 2.6.12
It was fixed in 2.4.27-11
And 2.6.8-16sarge1, which is available from 
http://kernel.alioth.debian.org/debian/ which will soon
become http://kernel.debian.net/debian/

-- 
Horms



Reply to: