Re: Roundcube Webmail 1.4.5

2020-06-03 Thread Dominic Hargreaves
On Wed, Jun 03, 2020 at 01:51:40PM +0200, Guilhem Moulin wrote: > Hi, > > On Wed, 03 Jun 2020 at 12:34:09 +0100, David Pottage wrote: > > Roundcube have just announced a new release which includes security > > fixes. > > > > What is the timeline to updated the Debian package in backports? > >

Re: [SECURITY] [DSA 4187-1] linux security update

2018-05-02 Thread Dominic Hargreaves
On Tue, May 01, 2018 at 05:12:02PM +, Ben Hutchings wrote: > - > Debian Security Advisory DSA-4187-1 secur...@debian.org > https://www.debian.org/security/Ben Hutchings > May

ownCloud security support

2016-05-04 Thread Dominic Hargreaves
Hi all, Firstly, thank you, David, for your excellent work packaging ownCloud and its dependencies. It allowed me a very easy setup for an installation which has been really valuable so far. (I will need to think carefully about future plans for this service.) Given the recent removal of

Re: [SECURITY] [DSA 3519-1] xen security update

2016-04-13 Thread Dominic Hargreaves
On Thu, Mar 17, 2016 at 10:52:03PM +0100, Moritz Muehlenhoff wrote: > Multiple security issues have been found in the Xen virtualisation > solution, which may result in denial of service or information disclosure. > > The oldstable distribution (wheezy) will be updated in a separate

Re: [SECURITY] [DSA 3481-1] glibc security update

2016-02-17 Thread Dominic Hargreaves
On Wed, Feb 17, 2016 at 07:31:49PM +0100, Thomas Hager wrote: > On Wed, 2016-02-17 at 10:55 +0000, Dominic Hargreaves wrote: > > "Mitigating factors for UDP include [...] > > - A local resolver (that drops non-compliant responses)." > > > > &qu

Re: [SECURITY] [DSA 3481-1] glibc security update

2016-02-17 Thread Dominic Hargreaves
On Tue, Feb 16, 2016 at 04:32:00PM +0100, Peter Ludikovsky wrote: > Hello, > > A question to those more knowledgeable: we're using our own DNS > servers for all lookups, and those do recursive lookup for any > external addresses. Am I right to assume that Bind9 uses it's own > implementation for

Re: Bug#810799: libcgi-session-perl: Perl DSA-3441-1 exposes taint bug in CGI::Session::Driver::file

2016-01-12 Thread Dominic Hargreaves
Control: tags -1 - security Control: found -1 4.46-1 On Tue, Jan 12, 2016 at 12:54:19PM +, Chris Boot wrote: > Control: tag -1 security > > On 12/01/16 12:28, Chris Boot wrote: > [snip] > > Forwarded: https://rt.cpan.org/Public/Bug/Display.html?id=80346 > > > > Dear Maintainer, > > > >

Re: [SECURITY] [DSA 3258-1] quassel security update

2015-05-13 Thread Dominic Hargreaves
On Tue, May 12, 2015 at 09:40:49PM +0200, Alessandro Ghedini wrote: It was discovered that the fix for CVE-2013-4422 in quassel, a distributed IRC client, was incomplete. This could allow remote attackers to inject SQL queries after a database reconnection (e.g. when the backend PostgreSQL

Re: [SECURITY] [DSA 2740-1] python-django security update

2013-08-28 Thread Dominic Hargreaves
On Fri, Aug 23, 2013 at 05:53:12PM +, Salvatore Bonaccorso wrote: Package: python-django Vulnerability : cross-site scripting vulnerability Problem type : remote Debian-specific: no Nick Brunn reported a possible cross-site scripting vulnerability in python-django, a

movabletype-opensource possible remote execute issue: workaround

2013-01-10 Thread Dominic Hargreaves
-bin/bugreport.cgi?bug=697666 but you may wish to temporarily disable access to mt-upgrade.cgi (which should not affect normal operation of MT) until this is released. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email

Re: [SECURITY] [DSA 2670-1] wordpress security update

2012-11-07 Thread Dominic Hargreaves
(and I'm not going to do all those investigations by myself). Mmm. I see a similar problem developing with Movable Type (which I am the sole maintainer for at the moment). I don't know what the answer is. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li

Re: [SECURITY] [DSA 2670-1] wordpress security update

2012-11-06 Thread Dominic Hargreaves
/wordpress-3-4-1/ and http://wordpress.org/news/2012/09/wordpress-3-4-2/ apply to 3.3 too? Are there any plans to further upgrade squeeze in this manner? Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email

Re: [SECURITY] [DSA 2480-2] request-tracker3.8 regression update

2012-05-31 Thread Dominic Hargreaves
On Wed, May 30, 2012 at 06:31:01PM +0100, Dominic Hargreaves wrote: On Tue, May 29, 2012 at 09:04:59PM +0200, Florian Weimer wrote: It was discovered that the recent request-tracker3.8 update, DSA-2480-1, introduced a regression which caused outgoing mail to fail when running under mod_perl

Re: [SECURITY] [DSA 2480-2] request-tracker3.8 regression update

2012-05-30 Thread Dominic Hargreaves
in this package. Please see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=674924 -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe

Re: [SECURITY] [DSA 2480-1] request-tracker3.8 security update

2012-05-25 Thread Dominic Hargreaves
), this problem has been fixed in version 4.0.5-3. RT 4 should not have been affected by this bug. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject

Re: [SECURITY] [DSA 2480-1] request-tracker3.8 security update

2012-05-25 Thread Dominic Hargreaves
On Fri, May 25, 2012 at 09:29:44AM +0100, Dominic Hargreaves wrote: On Thu, May 24, 2012 at 07:37:03PM +0200, Moritz Muehlenhoff wrote: Several vulnerabilities were discovered in Request Tracker, an issue tracking system: For the stable distribution (squeeze), this problem has been fixed

Re: Testers needed for Tomcat security update

2012-01-31 Thread Dominic Hargreaves
On Mon, Jan 30, 2012 at 01:55:57PM +, Dominic Hargreaves wrote: On Sun, Jan 29, 2012 at 01:14:20PM +0100, Moritz Mühlenhoff wrote: Moritz Mühlenhoff j...@inutil.org schrieb: Hi, the changes needed to secure Tomcat against the recent hash collision attack are large and instrusive

Re: Debian LTS?

2011-10-06 Thread Dominic Hargreaves
there (that's a big if, of course). Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Re: Debian LTS?

2011-10-05 Thread Dominic Hargreaves
than typical stable releases (eg 5 years, rather than the 2-3 that stable gets at the moment). -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject

Debian LTS?

2011-10-04 Thread Dominic Hargreaves
, so I assume that noone had the time to take it forward, but I thought it was worth checking whether anything had happened. Are there others on this list who would be willing to help support such an initiative? -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from

Re: [SECURITY] [DSA 2265-1] perl security update

2011-06-24 Thread Dominic Hargreaves
On Wed, Jun 22, 2011 at 10:26:48PM +0100, Dominic Hargreaves wrote: [adding perl maintainers to CC] On Wed, Jun 22, 2011 at 02:49:02PM -0400, Junior Gamez Aguilera wrote: after applying this upgrade mailscanner stop working, it start to enter in a continuous cicle of restart. please could

Re: [SECURITY] [DSA 2265-1] perl security update

2011-06-22 Thread Dominic Hargreaves
in unstable. Can you confirm that the errors on that thread match what you're seeing? Unfortunately there does not yet appear to be any sign of a real fix upstream, but there are a couple of possible workarounds mentioned. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from

sun-java6 updates for {old,}stable?

2011-02-21 Thread Dominic Hargreaves
Hello, Are there any plans to update the sun-java6 packages in lenny and squeeze for the recent floating point DoS issue? Thanks, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian

Re: sun-java6 updates for {old,}stable?

2011-02-21 Thread Dominic Hargreaves
On Mon, Feb 21, 2011 at 02:31:44PM +0100, Sylvestre Ledru wrote: Le lundi 21 février 2011 à 13:11 +, Dominic Hargreaves a écrit : Hello, Are there any plans to update the sun-java6 packages in lenny and squeeze for the recent floating point DoS issue? Yes: http://bugs.debian.org

Re: [SECURITY] [DSA-2158-1] cgiirc security update

2011-02-10 Thread Dominic Hargreaves
not be a disaster). Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive: http

Some obsolete packages on squeeze-security

2011-02-07 Thread Dominic Hargreaves
, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive: http

Some obsolete packages in squeeze-security

2011-02-07 Thread Dominic Hargreaves
-2.6.30 openoffice.org-l10n-lo Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Re: Upcoming changes in advisory format

2011-01-06 Thread Dominic Hargreaves
security updates, but I've never really persued it. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Missing DSA for xpdf update?

2010-12-21 Thread Dominic Hargreaves
Hello, xpdf 3.02-1.4+lenny3 has hit lenny-security but there doesn't seem to be any corresponding DSA yet. Is this an oversight? Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email

Re: btdownloadgui failed due to firewall

2010-07-18 Thread Dominic Hargreaves
. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org

request-tracker3.6 update

2010-01-24 Thread Dominic Hargreaves
Hi, CVE-2009-3892 is fixed in 3.6.7-5+lenny3. If someone can add me (alioth username 'dom' to be able to make these changes directly, I will do so. Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email

Re: [SECURITY] [DSA 1944-1] New request-tracker packages fix session hijack vulnerability

2009-12-03 Thread Dominic Hargreaves
in the above: testing does not contain a vulnerable version of RT; RT 3.6 has been kept out of testing as it is basically EOLed (and will be removed from unstable too once the new rtfm package has matured a bit), and RT 3.8.6 which fixes this is already in testing. Cheers, Dominic. -- Dominic

TEMP-0546829-001264 update

2009-11-10 Thread Dominic Hargreaves
not contain this problem. Thanks, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-tracker-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Re: Debian 4.0 and mmap_min_addr null pointer dereference flaw

2009-11-04 Thread Dominic Hargreaves
at upgrading my servers? The mmap_min_addr tuneabout was not introduced until after 2.6.18, which is the default etch kernel. I am using the 'etchnhalf' kernel (linux-image-2.6.24-etchnhalf*) on an etch machine, partly since it offers this protection. -- Dominic Hargreaves | http://www.larted.org.uk/~dom

Re: [SECURITY] [DSA 1836-1] New fckeditor packages fix arbitrary code execution

2009-07-20 Thread Dominic Hargreaves
version of the fckeditor. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Re: [SECURITY] [DSA 1807-1] New cyrus-sasl2/cyrus-sasl2-heimdal packages fix arbitrary code execution

2009-06-15 Thread Dominic Hargreaves
archive which appears to fix this problem, but no subsequent advisory has been released. Is this an oversight? Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ

Re: [SECURITY] [DSA 1807-1] New cyrus-sasl2/cyrus-sasl2-heimdal packages fix arbitrary code execution

2009-06-15 Thread Dominic Hargreaves
On Mon, Jun 15, 2009 at 06:10:29PM +0200, Nico Golde wrote: Hi, * Thijs Kinkhorst th...@debian.org [2009-06-15 17:39]: On Mon, June 15, 2009 16:42, Dominic Hargreaves wrote: For the oldstable distribution (etch), this problem will be fixed soon. 2.1.22.dfsg1-8+etch1 has now

Missing advisory for cyrus-sasl2?

2009-06-01 Thread Dominic Hargreaves
An update (2.1.22.dfsg1-23+lenny1) appeared in lenny-security over the weekend, but I haven't noticed an advisory for it on debian-security-announce or on the web site yet. An oversight? Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li

Any likely update for mod_jk?

2009-05-12 Thread Dominic Hargreaves
Hi, I wondered if any fix is likely to be available for CVE-2008-5519 (information disclosure, looks potentially quite severe) any time soon or if any more help is needed? Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web

Re: [SECURITY] [DSA 1794-1] New Linux 2.6.18 packages fix several vulnerabilities

2009-05-07 Thread Dominic Hargreaves
updates will typically release in a staggered or leap-frog fashion. i do not see this advisory (1794) @ http://www.debian.org/security Advisories take a little while to appear on the web site, I believe. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from

Re: [SECURITY] [DSA 1681-1] New Linux 2.6.24 packages fix several vulnerabilities

2008-12-11 Thread Dominic Hargreaves
? Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Re: [SECURITY] [DSA 1681-1] New Linux 2.6.24 packages fix several vulnerabilities

2008-12-11 Thread Dominic Hargreaves
? It would help reassure users that things haven't been forgotten about greatly. Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject

Re: [SECURITY] [DSA 1681-1] New Linux 2.6.24 packages fix several vulnerabilities

2008-12-11 Thread Dominic Hargreaves
On Thu, Dec 11, 2008 at 12:11:05PM -0700, dann frazier wrote: On Thu, Dec 11, 2008 at 06:49:59PM +, Dominic Hargreaves wrote: May I make a suggestion that you include a comment along these lines in the advisory texts? It would help reassure users that things haven't been forgotten

Re: [SECURITY] [DSA 1680-1] New clamav packages fix potential code execution

2008-12-10 Thread Dominic Hargreaves
dist, though, if you wanted it. Volatile admins, is there something wrong with this package or has it just been forgotten about? Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED

Re: [SECURITY] [DSA 1680-1] New clamav packages fix potential code execution

2008-12-10 Thread Dominic Hargreaves
On Wed, Dec 10, 2008 at 11:51:49AM +0100, Cyril Brulebois wrote: Dominic Hargreaves [EMAIL PROTECTED] (10/12/2008): Looks like it is in the etch-proposed-updates/etch dist, though, if you wanted it. Volatile admins, is there something wrong with this package or has it just been forgotten

Re: [SECURITY] [DSA 1680-1] New clamav packages fix potential codeexecution

2008-12-10 Thread Dominic Hargreaves
for volatile, as I understand it. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 1680-1] New clamav packages fix potential code execution

2008-12-05 Thread Dominic Hargreaves
-4etch16. For the unstable distribution (sid), these problems have been fixed in version 0.94.dfsg.2-1. This looks like quite a serious bug (remote arbitrary code execution). Are there any plans for an update to volatile? Thanks, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom

Re: [SECURITY] [DSA 1630-1] New Linux 2.6.18 packages fix several vulnerabilities

2008-09-04 Thread Dominic Hargreaves
kernels. Are they vulnerable to any of the issues discussed in this advisory, and if so will they be fixed? (As I understood it the etchnhalf kernels would be fully security supported). Thanks, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li

Re: Vacation messages (was: Re: [SECURITY] [DSA 1629-1] New postfix packages fix privilege escalation)

2008-08-18 Thread Dominic Hargreaves
mailing lists? Because this list is the Reply-To for debian-security-announce mails, and that list probably has an order of magnitude more subscribers than most, including, obviously, a greater proportion of misbehaving mail programs. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk

Re: [SECURITY] [DSA 1601-1] New wordpress packages fix several vulnerabilities

2008-07-04 Thread Dominic Hargreaves
On Fri, Jul 04, 2008 at 09:16:56AM +0200, Thijs Kinkhorst wrote: For the unstable distribution (sid), these problems have been fixed in version 2.3.3-1. Is this a mistake? packages.debian.org shows sid as having wordpress 2.5.1-4 currently... Dominic. -- Dominic Hargreaves | http

Re: [SECURITY] [DSA 1575-1] New Linux 2.6.18 packages fix denial of service

2008-05-13 Thread Dominic Hargreaves
On Mon, May 12, 2008 at 05:31:32PM -0600, dann frazier wrote: On Mon, May 12, 2008 at 11:52:27PM +0100, Dominic Hargreaves wrote: Is there any reason this has been labelled as a DoS rather than an potential arbitrary code execution issue (which http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008

Re: [SECURITY] [DSA 1575-1] New Linux 2.6.18 packages fix denial of service

2008-05-12 Thread Dominic Hargreaves
in the Debian kernel? It seems odd that Debian would release a new kernel for a single DoS-only vulnerability. Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Re: [SECURITY] [DSA 1565-1] New Linux 2.6.18 packages fix several vulnerabilities

2008-05-03 Thread Dominic Hargreaves
/version will give you the full version of the booted kernel. Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

ia32-libs security support

2008-03-17 Thread Dominic Hargreaves
quite a lot of .so files repackaged from the i386 binaries, and I'm concerned that these won't be security supported (I've seen no security updates for this package). Is my analysis correct, and I shouldn't install this package in a production environment? Thanks, Dominic. -- Dominic Hargreaves

Re: [SECURITY] [DSA 1435-1] New clamav packages fix several vulnerabilities

2007-12-19 Thread Dominic Hargreaves
in volatile.debian.org? Thanks, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 1430-1] New libnss-ldap packages fix denial of service

2007-12-11 Thread Dominic Hargreaves
certain confurations). It may be worth reissuing the advisory to make this clear. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact

Re: [DSA 1356-1] New Linux 2.6.18 packages fix several vulnerabilities

2007-08-16 Thread Dominic Hargreaves
will install corrected packages This won't work unless there are updated linux-image-2.6-* packages in security, will it? And even then, a dist-upgrade would be needed. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email

Re: [DSA 1356-1] New Linux 2.6.18 packages fix several vulnerabilities

2007-08-16 Thread Dominic Hargreaves
On Thu, Aug 16, 2007 at 09:34:58AM +0100, Dominic Hargreaves wrote: And even then, a dist-upgrade would be needed. Sorry to be replying to myself. Of course, this will also need module-assistant style (and any other) out-of-tree modules to be rebuilt; I can't remember whether there's ever been

Re: Packages being kept back after security notices

2007-06-15 Thread Dominic Hargreaves
OpenOffice.org depended on. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 1302-1] New freetype packages fix integer overflow

2007-06-11 Thread Dominic Hargreaves
fixed in version 2.2.1-5+etch1. For the unstable distribution (sid), this problem has been fixed in version 2.2.1-6. What is the status of the sarge packages? Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email

Re: security mirror out of date: 128.101.240.212

2007-05-14 Thread Dominic Hargreaves
round-robin, you should find the updated Packages file gets to you after a few tries. You may find a similar error - 404 when downloading the package, for the same reason. In that case, simply retry the apt-get upgrade until it works. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom

Re: [SECURITY] [DSA 1246-1] New OpenOffice.org packages fix arbitrary code execution

2007-01-08 Thread Dominic Hargreaves
/cgi-bin/search_packages.pl?keywords=openoffice.orgsearchon=namesversion=allrelease=all Regards, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe

Re: [SECURITY] [DSA-1236-1] New enemies-of-carlotta package fix missing sanity checks

2006-12-14 Thread Dominic Hargreaves
so I'd imagine it'll be in etch soon. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Register

2006-11-06 Thread Dominic Hargreaves
On Sun, Nov 05, 2006 at 08:27:36PM -0800, John Bugg wrote: Please register my name for update/upgrade notifications. Thanks in advance. You can do this from http://lists.debian.org/debian-security-announce/ Regards, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key

Re: Remote Root In Nvidia xserver Driver

2006-10-18 Thread Dominic Hargreaves
sensitive data. It's not an issue specific to this vulnerability. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Please change my eMail address

2006-10-13 Thread Dominic Hargreaves
-security-announce/ Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Update

2006-09-01 Thread Dominic Hargreaves
someone please confirm that -r3 is out now? There's an announcement on debian-announce sent out a couple of hours ago: http://lists.debian.org/debian-announce/debian-announce-2006/msg4.html Yes, it is out. Regards, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key

Re: Why is portmap installed by default?

2006-08-25 Thread Dominic Hargreaves
with nfs-common and lpr, removing it is one of the first things I do for a new install. Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe

Upgrading dovecot overwrites installed SSL keys

2006-05-29 Thread Dominic Hargreaves
am happy to provide the fix. Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 1071-1] New MySQL 3.23 packages fix several vulnerabilities

2006-05-22 Thread Dominic Hargreaves
to packages which have not been released or included as URLs in the advisory (mysql-dfsg 4.0.24-10sarge2, mysql-dfsg-4.1 4.1.11a-4sarge3). Will they be released on security.debian.org and have an advisory released? Cheers, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key

Re: how to display the SSHd fingerprint

2005-04-28 Thread Dominic Hargreaves
On Thu, Apr 28, 2005 at 07:24:11PM +0200, martin f krafft wrote: How can I find out the SSHD key fingerprint given the local file? ssh-keygen -l Cheers, -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email

Re: [SECURITY] [DSA 713-1] New junkbuster packages fix several vulnerabilities

2005-04-21 Thread Dominic Hargreaves
not sure what your subscription address is, you can find it encoded into the Return-path header of the list mails. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject