[Bug 356861] Re: OpenAFS Security Advisories 2009-001 and 2009-002

Launchpad Bug Tracker 356861 at bugs.launchpad.net
Thu Apr 16 22:22:49 UTC 2009


This bug was fixed in the package openafs - 1.4.9.dfsg1-0+ubuntu1

---------------
openafs (1.4.9.dfsg1-0+ubuntu1) jaunty; urgency=low

  * New upstream release.
    - OPENAFS-SA-2009-001: Avoid a potential kernel memory overrun if more
      items than requested are returned from an InlineBulk or BulkStatus
      message.  (CVE-2009-1251)  (LP: #356861)
    - OPENAFS-SA-2009-002: Avoid converting negative errors into invalid
      kernel memory pointers.  (CVE-2009-1250)  (LP: #356861)

 -- Anders Kaseorg <andersk at mit.edu>   Tue, 07 Apr 2009 16:41:24 -0400

** Changed in: openafs (Ubuntu Jaunty)
       Status: In Progress => Fix Released

-- 
OpenAFS Security Advisories 2009-001 and 2009-002
https://bugs.launchpad.net/bugs/356861
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs at lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs




More information about the universe-bugs mailing list