Bug#842987: redis: CVE-2016-2121: weak permissions on sensitive files

2016-11-03 Thread Chris Lamb
Hi Salvatore & Guido, > > So I decided to mark this no-dsa in wheezy. Please let me know if you > > guys don't think that's appropriate. > > Thanks for the analysis! Agreed, and think we will follow the same for > jessie as well. Thanks to both of you. I will keep this bug open and ensure

Bug#842987: redis: CVE-2016-2121: weak permissions on sensitive files

2016-11-03 Thread Salvatore Bonaccorso
Hi Guido, On Thu, Nov 03, 2016 at 09:05:41AM +0100, Guido Günther wrote: > Hi Salvatore, > On Wed, Nov 02, 2016 at 08:53:40PM +0100, Salvatore Bonaccorso wrote: > > Source: redis > > Version: 2:2.8.17-1 > > Severity: important > > Tags: security > > > > Hi > > > > See > > > >

Bug#842987: redis: CVE-2016-2121: weak permissions on sensitive files

2016-11-03 Thread Guido Günther
Hi Salvatore, On Wed, Nov 02, 2016 at 08:53:40PM +0100, Salvatore Bonaccorso wrote: > Source: redis > Version: 2:2.8.17-1 > Severity: important > Tags: security > > Hi > > See > > https://bugzilla.redhat.com/show_bug.cgi?id=1390588 > and > https://bugzilla.redhat.com/show_bug.cgi?id=1374700 >

Bug#842987: redis: CVE-2016-2121: weak permissions on sensitive files

2016-11-02 Thread Salvatore Bonaccorso
Source: redis Version: 2:2.8.17-1 Severity: important Tags: security Hi See https://bugzilla.redhat.com/show_bug.cgi?id=1390588 and https://bugzilla.redhat.com/show_bug.cgi?id=1374700 This partially seems to hold as well for Debian, at least for the /var/lib/redis part for unstable. For jessie