[Secure-testing-commits] r528 - sarge-checks/CAN

Micah Anderson micah@costa.debian.org
Tue, 08 Mar 2005 05:37:11 +0100


Author: micah
Date: 2005-03-08 05:37:08 +0100 (Tue, 08 Mar 2005)
New Revision: 528

Modified:
   sarge-checks/CAN/list
Log:
Failed to track down info on a kernel CAN


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2005-03-07 12:13:32 UTC (rev 527)
+++ sarge-checks/CAN/list	2005-03-08 04:37:08 UTC (rev 528)
@@ -2654,8 +2654,11 @@
 	NOTE: joshk says he doesn't understand this one
 	NOTE: looks like 2.4 is ok, 2.6.8 is vulnerable
 CAN-2004-1190 (SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not ...)
-	NOTE: micah checking with kernel team, need to track this down
-	NOTE: CAN URL is broken, <joshk> i've officially no idea what the bug is
+	NOTE: There are no useful details to be found on this, only vague information, I've tried to
+	NOTE: extract the patches from Suse kernels, to no avail, I've emailed some suse people...
+	NOTE: http://www.securityfocus.com/advisories/7579
+	NOTE: http://xforce.iss.net/xforce/xfdb/18370
+	NOTE: <joshk> i've officially no idea what the bug is
 	TODO: check with kernel team
 CAN-2004-1189 (The add_to_history function in svr_principal.c in libkadm5srv for MIT ...)
 	{DSA-629-1}