<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security">
    <title>gmane.linux.debian.devel.security</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17458"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17457"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17456"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17455"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17454"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17453"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17451"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17450"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17449"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17448"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17447"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17446"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17445"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17444"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17443"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17442"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17441"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17440"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17439"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.debian.devel.security/17438"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17458">
    <title>Re: [SECURITY] [DSA 2692-1] libxxf86vm security update</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17458</link>
    <description>&lt;pre&gt;Hi Moritz,

Thanks for the long update, I guess it would better if you send one mail
with libx*.
:) smile

Regards,
Diamondra


2013/5/23 Moritz Muehlenhoff &amp;lt;jmm&amp;lt; at &amp;gt;debian.org&amp;gt;



&lt;/pre&gt;</description>
    <dc:creator>Diamondra RAKOTOMAMONJY</dc:creator>
    <dc:date>2013-05-23T20:30:39</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17457">
    <title>Re: [SECURITY] [DSA 2692-1] libxxf86vm security update</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17457</link>
    <description>&lt;pre&gt;just the one, long, email would have been perfectly acceptable i feel.

On 23/05/13 17:27, Moritz Muehlenhoff wrote:


&lt;/pre&gt;</description>
    <dc:creator>col</dc:creator>
    <dc:date>2013-05-23T18:37:02</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17456">
    <title>Re: [SECURITY] [DSA 2692-1] libxxf86vm security update</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17456</link>
    <description>&lt;pre&gt;UNSUBSCRIBE

---------------------------------------------------------
Daniel J. Borello, E.I.T., LEED® AP
Ph.D. Candidate
University of Illinois at Urbana-Champaign
Email: dborello&amp;lt; at &amp;gt;illinois.edu
Website: http://www.DanielJBorello.com
Telephone: (847) 877-6287
---------------------------------------------------------


On Thu, May 23, 2013 at 11:27 AM, Moritz Muehlenhoff &amp;lt;jmm&amp;lt; at &amp;gt;debian.org&amp;gt; wrote:

&lt;/pre&gt;</description>
    <dc:creator>Dan Borello</dc:creator>
    <dc:date>2013-05-23T18:30:07</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17455">
    <title>RE: [SECURITY] [DSA 2676-1] libxfixes security update</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17455</link>
    <description>&lt;pre&gt;This has been sent about 6 times now

-------------------------------------------------------------------------
-------------------------------------------------------------------------
multiple
conversions,
to
version
version
version 1:5.0-
listmaster&amp;lt; at &amp;gt;lists.debian.org





This email, including attachments may be privileged, confidential and is intended exclusively for the addressee. The views expressed may not be official policy, but the personal views of the originator. If you have received this email in error please notify the sender and delete it from your system.  Emails are not secure and may contain viruses.  No liability can be accepted for viruses that might be transferred by this email or any attachment.


&lt;/pre&gt;</description>
    <dc:creator>Robin Abrahams</dc:creator>
    <dc:date>2013-05-23T17:50:38</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17454">
    <title>servicios de Diseño Web, programación, Posicionamiento Web Dominios y Hosting</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17454</link>
    <description>&lt;pre&gt;Estimados Sres /as, 
 
Tenemos el agrado de comunicarnos para ofrecerles nuestros servicios de Diseño Web, programación, Posicionamiento Web Dominios y Hosting. Contamos con la experiencia de 11 años en el mercado. 
- Diseño Web 
- Rediseño Web 
- Posicionamiento en buscadores. 
- Alojamiento Web 
- Registros de Dominios 
- Programación de Intranet y Extranet 
- Tiendas Virtuales con Pasarela de Pagos 
- Catálogos de Productos 
- E-learnings 
- Social Media 
Chats (Istalación gratis por 14 dias) 
- Y más. 
Desarrollamos sitios administrables por el usuario, logrando que usted tenga el total dominio y libertad del uso de su Web. Junto con cada Página desarrollada entregamos un Administrador para que pueda cargar datos, fotos, videos y todo el contenido necesario para mantener su Web actualizada. 
Atendemos agencias para reventa de productos y/o servicios / Marca Blanca / Distribuidores 
Estos son algunos de los clientes que han confiado en nosotros de "Madrid, Valencia, Burgos, Sevilla, Barcelona, G&lt;/pre&gt;</description>
    <dc:creator>Servicios WEB</dc:creator>
    <dc:date>2013-05-23T06:37:12</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17453">
    <title>Re: [SECURITY] [DSA 2669-1] linux security update</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17453</link>
    <description>&lt;pre&gt;unsubscribe
&lt;/pre&gt;</description>
    <dc:creator>Andrew S. Zbikowski</dc:creator>
    <dc:date>2013-05-20T17:28:18</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17451">
    <title>Re: Wheezy is vulnerable to CVE-2013-2094</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17451</link>
    <description>&lt;pre&gt;

Bug is in 2.6.37-3.8.8, fixed in 3.8.9 and kernel must be compiled with
PERF_EVENTS (default on most modern distros). Bug fixed in 3.8.10.

ref: https://news.ycombinator.com/item?id=5703758

Hope at this help

Regards, Riku


&lt;/pre&gt;</description>
    <dc:creator>Riku Valli</dc:creator>
    <dc:date>2013-05-15T14:02:48</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17450">
    <title>Re: Wheezy is vulnerable to CVE-2013-2094</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17450</link>
    <description>&lt;pre&gt;
Hi Kees,

I grabbed the source from here:-
http://packetstormsecurity.com/files/121616/semtex.c

Compiled it like so:-

gavin&amp;lt; at &amp;gt;caelyn:~$ gcc -O2 semtex.c &amp;amp;&amp;amp; ./a.out

As soon as I hit enter my kernel panics:-

" BUG: unable to handle kernel paging request at xxxxxxxxxxxxx. "

gavin&amp;lt; at &amp;gt;caelyn:~$ uname -a
Linux caelyn 3.2.0-4-amd64 #1 SMP Debian 3.2.41-2 x86_64 GNU/Linux

gavin&amp;lt; at &amp;gt;caelyn:~$ gcc -v
Using built-in specs.
COLLECT_GCC=gcc
COLLECT_LTO_WRAPPER=/usr/lib/gcc/x86_64-linux-gnu/4.7/lto-wrapper
Target: x86_64-linux-gnu
Configured with: ../src/configure -v --with-pkgversion='Debian
4.7.2-5' --with-bugurl=file:///usr/share/doc/gcc-4.7/README.Bugs
--enable-languages=c,c++,go,fortran,objc,obj-c++ --prefix=/usr
--program-suffix=-4.7 --enable-shared --enable-linker-build-id
--with-system-zlib --libexecdir=/usr/lib --without-included-gettext
--enable-threads=posix --with-gxx-include-dir=/usr/include/c++/4.7
--libdir=/usr/lib --enable-nls --with-sysroot=/ --enable-clocale=gnu
--enable-libstdcxx-debug --enable-libstdcxx-&lt;/pre&gt;</description>
    <dc:creator>Gavin</dc:creator>
    <dc:date>2013-05-15T11:32:47</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17449">
    <title>Re: Wheezy is vulnerable to CVE-2013-2094</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17449</link>
    <description>&lt;pre&gt;Gavin, did you use the right exploit? The output looks like it's designed
for a 2.6.37 kernel. I don't have a computer near me to check the exploit
myself. Could you please verify you used the right exploit? Thanks!
&lt;/pre&gt;</description>
    <dc:creator>Kees de Jong</dc:creator>
    <dc:date>2013-05-15T10:50:14</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17448">
    <title>Re: Wheezy is vulnerable to CVE-2013-2094</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17448</link>
    <description>&lt;pre&gt;Hi all.
I'm confirm exploit is working on Debian wheezy with kernel 
3.2.0-4-rt-amd64 with gcc -O2 options

On 05/15/2013 12:20 AM, Gavin wrote:


&lt;/pre&gt;</description>
    <dc:creator>nnex</dc:creator>
    <dc:date>2013-05-15T03:58:22</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17447">
    <title>Re: [SECURITY] [DSA 2668-1] linux-2.6 security update</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17447</link>
    <description>&lt;pre&gt;Apologies, hit the wrong reply to! Please ignore and thanks for all the good
work.

On Tue, May 14, 2013 at 09:15:48PM +0100, Jon Marshall wrote:

&lt;/pre&gt;</description>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2013-05-14T20:21:05</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17446">
    <title>Re: [SECURITY] [DSA 2668-1] linux-2.6 security update</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17446</link>
    <description>&lt;pre&gt;Saw this earlier, apparently there is a serious issue that affects all of the
kernels up to 3.8

Will do a security thing tomorrow, if I get a chance, but it has been a while
since we've had a look at it, my fault.

Will update once I've reviewed.

On Tue, May 14, 2013 at 01:14:29PM -0600, dann frazier wrote:

&lt;/pre&gt;</description>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2013-05-14T20:15:48</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17445">
    <title>Re: Wheezy is vulnerable to CVE-2013-2094</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17445</link>
    <description>&lt;pre&gt;
Ok, if I compile with the -O2 then I don't get a root shell, however
my kernel panics with:-

BUG: unable to handle kernel paging request at xxxxxxxxxxxxx.

Still not ideal.

Thanks for the heads-up!


&lt;/pre&gt;</description>
    <dc:creator>Gavin</dc:creator>
    <dc:date>2013-05-14T18:20:25</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17444">
    <title>Re: Wheezy is vulnerable to CVE-2013-2094</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17444</link>
    <description>&lt;pre&gt;
At first I thought the same thing, however compile with -O2:

$ gcc -O2 semtex.c &amp;amp;&amp;amp; ./a.out
2.6.37-3.x x86_64
sd&amp;lt; at &amp;gt;fucksheep.org 2010
root&amp;lt; at &amp;gt;xo-laptop:/tmp# uname -a
Linux xo-laptop 3.2.0-4-amd64 #1 SMP Debian 3.2.41-2 x86_64 GNU/Linux

&lt;/pre&gt;</description>
    <dc:creator>Gerald Turner</dc:creator>
    <dc:date>2013-05-14T17:41:19</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17443">
    <title>Re: Wheezy is vulnerable to CVE-2013-2094</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17443</link>
    <description>&lt;pre&gt;

Hi.

 I'm on the same kernel version/arch. Did you compile with -O2? I had to
compile with that flag for it to work.
&lt;/pre&gt;</description>
    <dc:creator>John Andreasson</dc:creator>
    <dc:date>2013-05-14T17:43:13</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17442">
    <title>Re: Wheezy is vulnerable to CVE-2013-2094</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17442</link>
    <description>&lt;pre&gt;
We're investigating it now and will provide a fix ASAP.

      -dann



&lt;/pre&gt;</description>
    <dc:creator>dann frazier</dc:creator>
    <dc:date>2013-05-14T17:29:05</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17441">
    <title>Re: Wheezy is vulnerable to CVE-2013-2094</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17441</link>
    <description>&lt;pre&gt;
Hi John,

I'm unable to replicate this 'issue' on my up to date Wheezy laptop.

gavin&amp;lt; at &amp;gt;caelyn:~$ uname -a
Linux caelyn 3.2.0-4-amd64 #1 SMP Debian 3.2.41-2 x86_64 GNU/Linux

When I run the compiled binary of this exploit as my unprivileged user
I get the following error:-

gavin&amp;lt; at &amp;gt;caelyn:~$ ./getroot
2.6.37-3.x x86_64
sd&amp;lt; at &amp;gt;f***sheep.org 2010
getroot: getroot.c:81: main: Assertion `p = memmem(code, 1024,
&amp;amp;needle, 8)' failed.
Aborted

What kernel are you able to replicate this bug with ?


&lt;/pre&gt;</description>
    <dc:creator>Gavin</dc:creator>
    <dc:date>2013-05-14T17:29:10</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17440">
    <title>Wheezy is vulnerable to CVE-2013-2094</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17440</link>
    <description>&lt;pre&gt;Hi.

Was just alerted of a kernel bug in RHEL [1], but when testing the sample
code on Wheezy as an unprivileged user it successfully gives me a root
prompt. Kind of suboptimal. :-(

Any idea when this is fixed?

[1] https://bugzilla.redhat.com/show_bug.cgi?id=962792
&lt;/pre&gt;</description>
    <dc:creator>John Andreasson</dc:creator>
    <dc:date>2013-05-14T16:36:12</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17439">
    <title>10 mai 2013 - Eclipse du Soleil</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17439</link>
    <description>&lt;pre&gt;


To unsubscribe copy and paste this link into a browser window - http://www.kiomail.com/sys/cremovecust.php?email=debian-security&amp;lt; at &amp;gt;lists.debian.org&amp;amp;list_id=5

&lt;/pre&gt;</description>
    <dc:creator>Clara V.S</dc:creator>
    <dc:date>2013-05-08T09:45:02</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17438">
    <title>Re: About adding security.debian.org ipv6 to iptables, which range should we add?</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17438</link>
    <description>&lt;pre&gt;Hello,

This one time, at band camp, Stefan Eriksson said:

security.debian.org is a set of mirrors, but what answer you get
depends on where in the world you appear to be coming from, and
maintenance periods and so on.

You can look here: http://db.debian.org/machines.cgi for all the
machines with a 'purpose' field set to 'security.debian.org mirror', and
hope that you can keep up to date, or you can use a web proxy for
outbound access.

Cheersm
&lt;/pre&gt;</description>
    <dc:creator>Stephen Gran</dc:creator>
    <dc:date>2013-05-07T19:07:07</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.debian.devel.security/17437">
    <title>Re: About adding security.debian.org ipv6 to iptables, which range should we add?</title>
    <link>http://permalink.gmane.org/gmane.linux.debian.devel.security/17437</link>
    <description>&lt;pre&gt;* Stefan Eriksson:


The IPv6 addresses change as well.  You should use a
tightly-controlled proxy or an internal mirror.


&lt;/pre&gt;</description>
    <dc:creator>Florian Weimer</dc:creator>
    <dc:date>2013-05-06T18:22:30</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.linux.debian.devel.security">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.linux.debian.devel.security</link>
  </textinput>
</rdf:RDF>
