|
|||||||||||
|
Re: [SECURITY] [DSA 1422-1] New e2fsprogs packages fix arbitrary code execution
From: Nico Golde <debian-security+ml(at)ngolde.de>
Date: Sat Dec 08 2007 - 08:07:20 EST
Oh ok. > If there are missing bits then we'll need to reissue the update, Ok, I am waiting for his reply, I attached my patch to the bug report in unstable. From what I see every multiplication with fs->blocksize needs to be checked, all of these are coming from the file system. Let's see what he does :) http://people.debian.org/~nion/nmu-diff/e2fsprogs-1.40.2-1_1.40.2-1+lenny1.patch
YFYI this is the patch I used for testing-security.
Cheers
-- Nico Golde - http://www.ngolde.de - nion(at)jabber.ccc.de - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. -- To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:54:23 EDT |
||||||||||
|
|||||||||||