Bug#448157: CVE-2007-5585 authentication bypass (FTBFS with patch)

2007-11-05 Thread Steffen Joeris
On Tue, 6 Nov 2007 01:52:56 pm Jamie Zawinski wrote: > On Nov 5, 2007, at 4:11 PM, Steffen Joeris wrote: > > With this patch, xscreensaver fails to build: > > Sorry, typo: pw->prompt_screen should have been pw->prompt_screen- > > >screen. Revised patch: The patch works and the crash is gone. I a

Bug#448157: CVE-2007-5585 authentication bypass (FTBFS with patch)

2007-11-05 Thread Jamie Zawinski
On Nov 5, 2007, at 4:11 PM, Steffen Joeris wrote: With this patch, xscreensaver fails to build: Sorry, typo: pw->prompt_screen should have been pw->prompt_screen- >screen. Revised patch: diff -u -r1.85 lock.c --- lock.c 10 Jul 2007 20:27:24 - 1.85 +++ lock.c 1 Nov 2007

Bug#448157: CVE-2007-5585 authentication bypass (FTBFS with patch)

2007-11-05 Thread Steffen Joeris
With this patch, xscreensaver fails to build: lock.c: In function ‘update_passwd_window’: lock.c:1082: error: ‘saver_screen_info’ has no member named ‘root_depth’ make[2]: *** [lock.o] Error 1 make[2]: Leaving directory `/home/white/white/debian/debs/security/xscreensaver/new/xscreensaver-5.03/dr

Bug#448157: CVE-2007-5585 authentication bypass

2007-11-01 Thread Jamie Zawinski
I don't understand how xscreensaver-gl-helper not being installed could cause this sort of thing. However, this does sound vaguely like another bug: can one of you who is able to reproduce the problem try this patch and let me know if it works? Thanks... diff -u -r1.85 lock.c --- lock.c

Bug#448157: CVE-2007-5585 authentication bypass

2007-10-27 Thread Jose Luis Rivas Contreras
reassign 448157 xscreensaver quit Ari Pollak wrote: > The point here is that xscreensaver should not unlock the screen when > missing xscreensaver-gl-helper, it should just display a blank > screensaver. rss-glx does not NEED to be run with xscreensaver-gl-helper > as it's perfectly feasible to ru

Processed: Re: Bug#448157: CVE-2007-5585 authentication bypass

2007-10-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign 448157 xscreensaver Bug#448157: CVE-2007-5585 authentication bypass Bug reassigned from package `rss-glx' to `xscreensaver'. > quit Stopping processing here. Please contact me if you need assistance. Debian bug tracking syst

Bug#448157: CVE-2007-5585 authentication bypass

2007-10-27 Thread Ari Pollak
The point here is that xscreensaver should not unlock the screen when missing xscreensaver-gl-helper, it should just display a blank screensaver. rss-glx does not NEED to be run with xscreensaver-gl-helper as it's perfectly feasible to run with gnome-screensaver, so rss-glx shouldn't need to depend

Bug#448157: CVE-2007-5585 authentication bypass

2007-10-27 Thread Jose Luis Rivas Contreras
Nico Golde wrote: > Hi Jose, > * Jose Luis Rivas Contreras <[EMAIL PROTECTED]> [2007-10-27 17:40]: >> There's no such `xscreensaver-gl-extras' package, xscreensaver-gl-helper >> is installed with `xscreensaver-gl' so `rss-glx' should really suggests >> xscreensaver-gl instead of xscreensaver. > >

Bug#448157: CVE-2007-5585 authentication bypass

2007-10-27 Thread Nico Golde
Hi Jose, * Jose Luis Rivas Contreras <[EMAIL PROTECTED]> [2007-10-27 17:40]: > There's no such `xscreensaver-gl-extras' package, xscreensaver-gl-helper > is installed with `xscreensaver-gl' so `rss-glx' should really suggests > xscreensaver-gl instead of xscreensaver. Yes but this would only worka

Bug#448157: CVE-2007-5585 authentication bypass

2007-10-27 Thread Jose Luis Rivas Contreras
reassign 448157 rss-glx thanks Hi, There's no such `xscreensaver-gl-extras' package, xscreensaver-gl-helper is installed with `xscreensaver-gl' so `rss-glx' should really suggests xscreensaver-gl instead of xscreensaver. [EMAIL PROTECTED]:~$ dpkg -S /usr/bin/xscreensaver-gl-helper xscreensaver-g

Bug#448157: CVE-2007-5585 authentication bypass

2007-10-26 Thread Nico Golde
Package: rss-glx Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for rss-glx. CVE-2007-5585[0]: | xscreensaver 5.03 and earlier, when running without | xscreensaver-gl-extras (GL extras) installed, crashes when | /usr/bin/xscreensaver-gl-