Bug#559806: Bug#559816: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Dirk Eddelbuettel
On 8 December 2009 at 18:00, Michael Gilbert wrote: | On Tue, 8 Dec 2009 15:02:42 -0600, Dirk Eddelbuettel wrote: | > | > Just as a further follow-up and Ack! -- I have seen the bug report; I would | > appreciate news as to whether we can expect a new libtool or whether we are | > expected to dea

Bug#559806: Bug#559816: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Michael Gilbert
On Tue, 8 Dec 2009 15:02:42 -0600, Dirk Eddelbuettel wrote: > > Just as a further follow-up and Ack! -- I have seen the bug report; I would > appreciate news as to whether we can expect a new libtool or whether we are > expected to deal with this ourselves. you can expect a new libtool (at least

Bug#559806: Bug#559816: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Dirk Eddelbuettel
Just as a further follow-up and Ack! -- I have seen the bug report; I would appreciate news as to whether we can expect a new libtool or whether we are expected to deal with this ourselves. Dirk -- Three out of two people have difficulties with fractions. -- To UNSUBSCRIBE, email to debian-

Bug#559816: CVE-2009-3736 local privilege escalation

2009-12-06 Thread Michael Gilbert
Package: jags Severity: grave Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) id was published for libtool. I have determined that this package embeds a vulnerable copy of the libtool source code. However, since this is a mass bug filing (due to so many packages embedd