oss-sec mailing list archives
Re: [FD] [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell
From: Hector Marco <hecmargi () upv es>
Date: Tue, 15 Nov 2016 20:11:11 +0000
Hello, It would be more precise to say "2:1.7.3-2" rather than "2:1". This number refers to the Debian package. It seems that Debian is using different version numbers for the "cryptsetup" package: https://security-tracker.debian.org/tracker/CVE-2016-4484 We are not sure whether the last part of the version number (2:1.7.3-2) of the Debian package (1.7.3-2) is used to match with the cryptsetup version. Just to avoid confusion, the bug is on the scripts (initramfs) and not in the cryptsetup encryption/decryption algorithms. Regards, Hector Marco & Ismael Ripoll.
On Mon, Nov 14, 2016 at 08:45:51PM +0000, Hector Marco wrote:Hello All, Affected package ---------------- Cryptsetup <= 2:1Hi, Can you clarify which versions are affected? The latest upstream version is 1.7.3: https://gitlab.com/cryptsetup/cryptsetup/commits/master What is the 2:1 version?
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- CVE-2016-4484: - Cryptsetup Initrd root Shell Hector Marco (Nov 14)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell - Update: Dracut is also vulnerable Hector Marco-Gisbert (Nov 14)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell Leo Famulari (Nov 14)
- Re: [FD] [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell Hector Marco (Nov 15)
- Re: Re: [FD] [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell Jeremy Stanley (Nov 15)
- Re: [FD] [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell Hector Marco (Nov 15)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell Jason Cooper (Nov 16)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell John Haxby (Nov 16)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell Jason Cooper (Nov 17)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell John Haxby (Nov 17)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell Jason Cooper (Nov 17)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell John Haxby (Nov 17)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell Jacobo Avariento (Nov 17)
- Linux encrypted boot security, was: CVE-2016-4484: - Cryptsetup Initrd root Shell Jason Cooper (Nov 18)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell John Haxby (Nov 16)