Bug#559845: CVE-2009-3736 local privilege escalation

2009-12-15 Thread Simon Horman
On Tue, Dec 08, 2009 at 10:41:20AM +1100, Simon Horman wrote: > On Mon, Dec 07, 2009 at 11:12:32PM +1100, Simon Horman wrote: > > On Mon, Dec 07, 2009 at 12:11:07AM -0500, Michael Gilbert wrote: > > > Package: heartbeat > > > Severity: grave > > > Tags: security > > > > > > Hi, > > > > > > The fo

Bug#559845: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Simon Horman
On Mon, Dec 07, 2009 at 11:12:32PM +1100, Simon Horman wrote: > On Mon, Dec 07, 2009 at 12:11:07AM -0500, Michael Gilbert wrote: > > Package: heartbeat > > Severity: grave > > Tags: security > > > > Hi, > > > > The following CVE (Common Vulnerabilities & Exposures) id was > > published for libtoo

Bug#559845: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Simon Horman
On Mon, Dec 07, 2009 at 12:11:07AM -0500, Michael Gilbert wrote: > Package: heartbeat > Severity: grave > Tags: security > > Hi, > > The following CVE (Common Vulnerabilities & Exposures) id was > published for libtool. I see that heartbeat in unstable no longer > embeds libtool, but it appears

Bug#559845: CVE-2009-3736 local privilege escalation

2009-12-06 Thread Michael Gilbert
Package: heartbeat Severity: grave Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) id was published for libtool. I see that heartbeat in unstable no longer embeds libtool, but it appears that etch and lenny still have it. I am not sure if it is actually used in the bin