Re: [SECURITY] [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution

2004-10-14 Thread Loïc Minier
Loïc Minier <[EMAIL PROTECTED]> - Wed, Oct 13, 2004: > I did not see an entry in the changelog for that one, is another upload > pending? Was I actually the only one getting tar segfaults? -- Loïc Minier <[EMAIL PROTECTED]> -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "

Re: [SECURITY] [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution

2004-10-12 Thread Loïc Minier
Loïc Minier <[EMAIL PROTECTED]> - Tue, Oct 12, 2004: > It seems it is already known by debian developers, but a note for > upgraders: there is a separate issue on *some* machines where dpkg will > fail because its tar subprocess segfaults: > Unpacking replacement libsasl7 ... > dpkg-deb: su

Re: [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution

2004-10-12 Thread Henrique de Moraes Holschuh
On Tue, 12 Oct 2004, Andreas Barth wrote: > * Henrique de Moraes Holschuh ([EMAIL PROTECTED]) [041012 17:10]: > > Since I did the NMUs for sid/sarge, I wonder if there is something wrong > > with the patch for SASL 1.5? It seems to work very well in SASL 2, but if it > > is going bonkers on SASL 1.

Re: [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution

2004-10-12 Thread Andreas Barth
* Henrique de Moraes Holschuh ([EMAIL PROTECTED]) [041012 17:10]: > Since I did the NMUs for sid/sarge, I wonder if there is something wrong > with the patch for SASL 1.5? It seems to work very well in SASL 2, but if it > is going bonkers on SASL 1.5, I will have to re-NMU it to fix it in sid and >

Re: [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution

2004-10-12 Thread Henrique de Moraes Holschuh
On Tue, 12 Oct 2004, Andreas Barth wrote: > * Philip Ross ([EMAIL PROTECTED]) [041012 16:30]: > > This update for woody has broken ldapsearch form ldap-utils. ldapsearch > > now segfaults at startup. > > Please downgrade for the moment, there is an issue with the update. We > know the reason, and

Re: [SECURITY] [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution

2004-10-12 Thread Loïc Minier
Martin Schulze <[EMAIL PROTECTED]> - Tue, Oct 12, 2004: > Package: cyrus-sasl It seems it is already known by debian developers, but a note for upgraders: there is a separate issue on *some* machines where dpkg will fail because its tar subprocess segfaults: Unpacking replacement libs

Re: [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution

2004-10-12 Thread Andreas Barth
* Philip Ross ([EMAIL PROTECTED]) [041012 16:30]: > This update for woody has broken ldapsearch form ldap-utils. ldapsearch > now segfaults at startup. Please downgrade for the moment, there is an issue with the update. We know the reason, and I hope that a fixed package will be available soon. P

Re: [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution

2004-10-12 Thread Philip Ross
Martin Schulze wrote: - -- Debian Security Advisory DSA 563-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze October 12th, 2004 http://www.d

Re: [SECURITY] [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution

2004-10-12 Thread Jérôme RICHARD
Hello, After upgrading libsasl7, slapd does a segmentation fault and don't start !! I had to downgrade libsasl7 to fix it ! Regards, Jerome. Le 12 oct. 04, à 14:52, Martin Schulze a écrit : -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 -