From mboxrd@z Thu Jan 1 00:00:00 1970 From: ludo@gnu.org (Ludovic =?utf-8?Q?Court=C3=A8s?=) Subject: Re: [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell Date: Tue, 15 Nov 2016 11:35:12 +0100 Message-ID: <87vavpdo9r.fsf@gnu.org> References: <88958a9e-25c1-97ce-1800-bc4bff93d9a9@hmarco.org> <20161115032707.GA5104@jasmine> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:35143) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1c6b5D-0001W9-BW for guix-devel@gnu.org; Tue, 15 Nov 2016 05:35:20 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1c6b59-0004fC-5g for guix-devel@gnu.org; Tue, 15 Nov 2016 05:35:19 -0500 In-Reply-To: <20161115032707.GA5104@jasmine> (Leo Famulari's message of "Mon, 14 Nov 2016 22:27:07 -0500") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari Cc: guix-devel Hi Leo, Leo Famulari skribis: > On Mon, Nov 14, 2016 at 08:45:51PM +0000, Hector Marco wrote: >> Hello All, >>=20 >> Affected package >> ---------------- >> Cryptsetup <=3D 2:1 > > Hi, > > Can you clarify which versions are affected? > > The latest upstream version is 1.7.3: > > https://gitlab.com/cryptsetup/cryptsetup/commits/master > > What is the 2:1 version? FWIW GuixSD does not use the vulnerable shell scripts mentioned in . They are not even installed in our =E2=80=98cryptsetup=E2=80=99 package. Ludo=E2=80=99.