Bug#700923: [Secure-testing-team] Bug#700923: pacemaker: CVE-2013-0281

2013-03-02 Thread Thijs Kinkhorst
severity 700923 important thanks Hi, I find it unlikely that in serious deployments remote cib management would be enabled for untrusted connections. This kind of management usually happens over separate networks or is appropriately guarded by other controls. And where not, the worst result

Bug#700923: [Secure-testing-team] Bug#700923: pacemaker: CVE-2013-0281

2013-03-01 Thread Yves-Alexis Perez
On mar., 2013-02-19 at 12:35 +0100, Moritz Muehlenhoff wrote: Package: pacemaker Severity: grave Tags: security Justification: user security hole Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0281 for details and a link to the upstream fix. Due to the Wheezy freeze