Bug#449108: CVE-2007-3920: bypass password authentication

2007-11-05 Thread Lubomir Kundrak
Please note that Red Hat believes that the attached patch is not completly correct. See the Red Hat bugzilla entry for justification and another patch: https://bugzilla.redhat.com/show_bug.cgi?id=350271 -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL P

Bug#449108: CVE-2007-3920: bypass password authentication

2007-11-05 Thread Lubomir Kundrak
Whoops, I am terribly sorry for the noise. In fact I did not notice that this is a different patch from proposed upstream one and is likely to be correct. -- Lubomir Kundrak (Red Hat Security Response Team) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Troubl

Bug#449108: CVE-2007-3920: bypass password authentication

2007-11-02 Thread Steffen Joeris
Package: compiz Severity: grave Tags: security Justification: user security hole Hi The following CVE[0] has been issued for gnome-screensaver and compiz. gnome-screensaver is already fixed, but compiz also seems to be affected. Here is the text CVE-2007-3920: GNOME screensaver 2.20 in Ubuntu 7