WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

Re: [Xen-devel] [PATCH] Fix CVE-2007-1320, CVE-2007-1321 , CVE-2007-132

To: Keir Fraser <Keir.Fraser@xxxxxxxxxxxx>
Subject: Re: [Xen-devel] [PATCH] Fix CVE-2007-1320, CVE-2007-1321 , CVE-2007-1322, CVE-2007-1323 and CVE-2007-1366
From: "S.Çağlar Onur" <caglar@xxxxxxxxxxxxx>
Date: Tue, 1 May 2007 23:46:02 +0300
Cc: xen-devel@xxxxxxxxxxxxxxxxxxx
Delivery-date: Tue, 01 May 2007 13:44:54 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <C25D5DA6.6AE5%Keir.Fraser@xxxxxxxxxxxx>
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
Organization: TÜBİTAK / UEKAE
References: <C25D5DA6.6AE5%Keir.Fraser@xxxxxxxxxxxx>
Reply-to: caglar@xxxxxxxxxxxxx
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: KMail/1.9.6
01 May 2007 Sal tarihinde, Keir Fraser şunları yazmıştı: 
> On 1/5/07 19:56, "S.Çağlar Onur" <caglar@xxxxxxxxxxxxx> wrote:
> > Hmm i think there are some :)
> >
> > I have following patches on top of current 3.0.5-testing tree, this
> > series contains all released CVE's from 2.6.18 to up until now (linus's
> > current git), only CVE-2007-2242 ( IPV6: Disallow RH0 by default.) is
> > missing...
>
> Presumably we'd get most of these by upgrading to linux-2.6.18.8?

8 of them are in 2.6.18.8 others are backported/applied etc,

CVE-2005-4352.patch <- solved with 2.6.18.3
CVE-2006-4814.patch <- solved with 2.6.18.8 
CVE-2006-5619.patch <- solved with 2.6.18.2
CVE-2006-5749.patch <- solved with 2.6.20-rc2
CVE-2006-5751.patch <- solved with 2.6.18.4
CVE-2006-5753.patch <- solved with 2.6.20-rc4
CVE-2006-5757-CVE-2006-6060.patch <- solved in 2.6.18.8
CVE-2006-5823.patch <- solved with 2.6.20-rc1
CVE-2006-6053.patch <- solved with 2.6.20-rc1
CVE-2006-6054.patch <- solved with 2.6.20-rc1
CVE-2006-6056.patch <- solved with 2.6.18.8 
CVE-2006-6106.patch <- solved with 2.6.18.6
CVE-2006-6333.patch <- solved with 2.6.20
CVE-2007-0005.patch <- solved with 2.6.21-rc3
CVE-2007-0006.patch <- solved with 2.6.21
CVE-2007-0772.patch <- solved with 2.6.18.7
CVE-2007-0958.patch <- solved with 2.6.20-rc7
CVE-2007-1000.patch <- solved with 2.6.21
CVE-2007-1217.patch <- solved with 2.6.20.1
CVE-2007-1388.patch <- solved with 2.6.21
CVE-2007-1497.patch <- solved with 2.6.21
CVE-2007-1592.patch <- solved with 2.6.21
CVE-2007-1861.patch <- solved with 2.6.21.1
CVE-2007-2172.patch <- solved with 2.6.20.6

Cheers
-- 
S.Çağlar Onur <caglar@xxxxxxxxxxxxx>
http://cekirdek.pardus.org.tr/~caglar/

Linux is like living in a teepee. No Windows, no Gates and an Apache in house!

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel