Bug#544756: linux-image-2.6.26-2-686: Kernel still vulnerable by dsa-1862

2009-09-02 Thread Christoph Siess
Package: linux-image-2.6.26-2-686 Version: 2.6.26-17lenny2 Severity: critical Tags: security Justification: root security hole Hi, according to http://www.debian.org/security/2009/dsa-1862 this Version of the 2.6.26-2 Kernel should not be vulnerable to CVE-2009-2692. Unfortunately I'm still ab

Bug#544756: linux-image-2.6.26-2-686: Kernel still vulnerable by dsa-1862

2009-09-02 Thread Florian Weimer
* Christoph Siess: > Correct my if I got something wrong, but according to my > understanding this shouldn't be possible with version > 2.6.26-17lenny2. Correct. > Linux version 2.6.26-2-686 (Debian 2.6.26-17lenny1) (da...@debian.org) (gcc > version 4.1.3 20080704 (prerelease) (Debian 4.1.2-25)

Bug#544756: linux-image-2.6.26-2-686: Kernel still vulnerable by dsa-1862

2009-09-02 Thread Christoph Siess
On Wed, Sep 02, 2009 at 07:00:49PM +, Florian Weimer wrote: > * Christoph Siess: > > > > Linux version 2.6.26-2-686 (Debian 2.6.26-17lenny1) (da...@debian.org) (gcc > > version 4.1.3 20080704 (prerelease) (Debian 4.1.2-25)) #1 SMP Sun Jul 26 > > 21:25:33 UTC 2009 > > But it seems you are r

Bug#544756: linux-image-2.6.26-2-686: Kernel still vulnerable by dsa-1862

2009-09-02 Thread Moritz Muehlenhoff
On Wed, Sep 02, 2009 at 08:45:20PM +0200, Christoph Siess wrote: > Package: linux-image-2.6.26-2-686 > Version: 2.6.26-17lenny2 > Severity: critical > Tags: security > Justification: root security hole > > > Hi, > > according to http://www.debian.org/security/2009/dsa-1862 this Version of the >

Re: Bug#544756: linux-image-2.6.26-2-686: Kernel still vulnerable by dsa-1862

2009-09-02 Thread Bjørn Mork
Christoph Siess writes: > I'm very, sorry - I forgot to run lilo :(. Maybe #535331 should get a security tag? It does deserve to get fixed both in lenny and etchnhalf IMHO, so the severity should be increased at some point. But I was kind of hoping that the kernel team would just add the build

Bug#544756: [Secure-testing-team] Bug#544756: linux-image-2.6.26-2-686: Kernel still vulnerable by dsa-1862

2009-09-03 Thread Micah Anderson
* Christoph Siess [2009-09-02 14:57-0400]: > Package: linux-image-2.6.26-2-686 > Version: 2.6.26-17lenny2 > Severity: critical > Tags: security > Justification: root security hole > > > Hi, > > according to http://www.debian.org/security/2009/dsa-1862 this Version of the > 2.6.26-2 Kernel shou