Re: Patches for CVE-2011-0009

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 01/27/2011 12:43 AM, Xavier Bachelot wrote:
> On 01/26/2011 09:16 PM, Xavier Bachelot wrote:
>> On 01/26/2011 12:00 AM, Xavier Bachelot wrote:
>>> Hi,
>>>
>>> I've been looking at the issue for both rt 3.6 and 3.8.
>>> I have a rather full featured patch for 3.8 and I took the Debian patch
>>> for 3.6. However, I'm not happy with 3.6, it's lacking the script to fix
>>> all the passwords. I'll try to come up with something better in the next
>>> few days. Here's my WIP for reference.
>>>
>>> Regards,
>>> Xavier
>>
>> Here are the updated patches against master and el5 branches. I only
>> have an rt 3.6 to test against, so the 3.8 patch is not run time tested,
>> but I'm confident.
>> The only missing bit is a paragraph about the password mass-update
>> script in the UPGRADING file for 3.6.
>>
> Sorry, slightly wrong patches, it was missing the patch to the UPGRADING
> file. Here is a fixed one for 3.8. I've pushed the 3.6 patch to el5.
>
> http://koji.fedoraproject.org/koji/taskinfo?taskID=2744662
> https://admin.fedoraproject.org/updates/rt3-3.6.10-2.el5
>
> Ralf, Mark, I let you give a test at 3.8 on Rawhide/F14/F13 and EL6,
> respectively.

Xavier, please don't try to rush it.

So far, from visual inspection only, I am not necessarily opposed to 
your patch but I like the debian patches more.

Ralf
--
Fedora Extras Perl SIG
http://www.fedoraproject.org/wiki/Extras/SIGs/Perl
perl-devel mailing list
perl-devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/perl-devel


[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Legacy Announce]     [Fedora PHP Devel]     [Kernel Devel]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Big List of Linux Books]     [Gimp]     [Yosemite Information]
  Powered by Linux