Re: sun-java6 updates for {old,}stable?

2011-03-09 Thread Harald Weidner
Hello,

Dominic Hargreaves d...@earth.li:

  Are there any plans to update the sun-java6 packages in lenny and
  squeeze for the recent floating point DoS issue?

 Yes:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=613723
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=613741

Great, thanks (and I see that candidate packages are available too).

This topic is already some days old but I still can't find the new
packages in the repos for squeeze and lenny.

Is it planned to upload them on security.debian.org? And when?

Regards,
Harald


-- 
To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/il7ct2$bbv$1...@m31s16.vlinux.de



Re: sun-java6 updates for {old,}stable?

2011-03-09 Thread Jonathan Wiltshire
On Wed, Mar 09, 2011 at 08:14:26AM +, Harald Weidner wrote:
 This topic is already some days old but I still can't find the new
 packages in the repos for squeeze and lenny.
 
 Is it planned to upload them on security.debian.org? And when?

The packages are non-free, so they do not get security support. They will
be in the next point release for Squeeze in a few weeks [1].

1: http://release.debian.org/proposed-updates/stable.html

-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51


signature.asc
Description: Digital signature


CVE Exploit

2011-03-09 Thread aizaz83 hussain
Dear I need your Help regarding Exploit development of CVE-2010-3872
Could you please Guide.
How might this CVE-2010-3872 be exploited and how might an exploit work


Thanks and Regards 
Muhammad Hussain



Re: CVE Exploit

2011-03-09 Thread Timothy Ball
On Wed, Mar 09, 2011 at 01:31:50AM -0800, aizaz83 hussain wrote:
 Dear I need your Help regarding Exploit development of CVE-2010-3872
 Could you please Guide.
 How might this CVE-2010-3872 be exploited and how might an exploit work
 

bwahahahahaha ... thanks this was a pretty good pick-me-up . 

read-code-write-0day ur-own-damn-self . 

need a hint ? pointer walk FTW !!!

--timball

ps) no i won't help u write 0day

-- 
GPG key available on pgpkeys.mit.edu
pub  1024D/511FBD54 2001-07-23 Timothy Lu Hu Ball timb...@tux.org
Key fingerprint = B579 29B0 F6C8 C7AA 3840  E053 FE02 BB97 511F BD54


-- 
To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/20110309192655.ga30...@gwyn.tux.org



Re: CVE Exploit

2011-03-09 Thread Jordon Bedwell

On 3/9/2011 1:26 PM, Timothy Ball wrote:

On Wed, Mar 09, 2011 at 01:31:50AM -0800, aizaz83 hussain wrote:

Dear I need your Help regarding Exploit development of CVE-2010-3872
Could you please Guide.
How might this CVE-2010-3872 be exploited and how might an exploit work


bwahahahahaha ... thanks this was a pretty good pick-me-up .

read-code-write-0day ur-own-damn-self .

need a hint ? pointer walk FTW !!!

--timball

ps) no i won't help u write 0day



Damn, beat me to it man. Though I don't think it's a 0day anymore, it's 
been fixed in Debian.

http://security-tracker.debian.org/tracker/CVE-2010-3872


--
To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/4d78087e.1080...@envygeeks.com