Bug#688956: dracut: CVE-2012-4453: creates non-world readable initramfs images

2013-01-18 Thread Jonathan Wiltshire
Package: dracut Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.7) -

Bug#688956: dracut: CVE-2012-4453: creates non-world readable initramfs images

2012-10-09 Thread Moritz Muehlenhoff
On Thu, Sep 27, 2012 at 01:41:22PM +0200, Thomas Lange wrote: On Thu, 27 Sep 2012 14:32:46 +0300, Henri Salo he...@nerv.fi said: I haven't verified Debian packages are affected. If you want me to do it send me an email :) That would be great, because currently I'm very busy. Debian

Bug#688956: dracut: CVE-2012-4453: creates non-world readable initramfs images

2012-09-27 Thread Henri Salo
Package: dracut Version: 020-1 Severity: important Tags: security An information disclosure flaw was found in the way dracut, an initramfs root filesystem images generator, created initramfs images. When the root filesystem contained sensitive information (password based authentication for iSCSI

Bug#688956: dracut: CVE-2012-4453: creates non-world readable initramfs images

2012-09-27 Thread Thomas Lange
On Thu, 27 Sep 2012 14:32:46 +0300, Henri Salo he...@nerv.fi said: I haven't verified Debian packages are affected. If you want me to do it send me an email :) That would be great, because currently I'm very busy. -- regards Thomas -- To UNSUBSCRIBE, email to