Bug#860981: CVE-2016-4484 still Exists

2017-05-18 Thread ??. ?
Well, since Red Hat is not going to take any action, I think you are right https://access.redhat.com/security/cve/cve-2016-4484 Best Regards, XU Guang-zhao

Bug#860981: [pkg-cryptsetup-devel] Bug#860981: CVE-2016-4484 still Exists

2017-05-12 Thread ??. ?
Dear Guilhem, Well when installing a Debian system and enabling encryption in https://anonscm.debian.org/cgit/d-i/partman-crypto.git/, the `panic` kernel parameter will not be automatically added, so I don't think everyone who has enabled full-disk encryption will disable the debug shell. If n

Bug#860981: CVE-2016-4484 still Exists

2017-04-22 Thread ??. ?
Package: cryptsetup Version: 2:1.7.3-3 Severity: critical When logging in to an encrypted system, just press the ENTER button for about half an hour (or you may just put a stone on your keyboard) and you will be provided with a initramfs shell in which you or someone nasty can modify something