Re: Appuntamento con il nuovo ciclo di lectiones magistrales di AFIP International

2018-12-11 Thread Casper Madsen
Please ban this from the list!

> Den 11. dec. 2018 kl. 19.02 skrev Sprea Editori :
> 
> Profilo completo al 5%Aggiornalo ora per accedere a tutti i serviziProcedi
> Se non visualizzi correttamente questo messaggio, clicca qui
>  
>
> AL VIA IL NUOVO CICLO DI LECTIONES MAGISTRALES
> 
> ORGANIZZATE DA AFIP INTERNATIONAL
> 
> PRESSO LA TRIENNALE DI MILANO
> 
>  
> 
> Il significato, il ruolo e il valore dell’immagine, della comunicazione 
> visiva e dell’arte:
> 
> l’esperienza e il punto di vista di personaggi di spicco del mondo della 
> fotografia
> 
> in dialogo con eccellenze e professionalità del settore
> 
>  
> 
> Primo appuntamento
> 
> MERCOLEDÌ 5 DICEMBRE - ORE 19
> 
> “RAPPRESENTARE LO SPAZIO, DAL DISEGNO ALLA FOTOGRAFIA”
> 
> MARCO INTROINI
> 
> CONVERSAZIONE CON MADDALENA D’ALFONSO ED EMANUELE PICCARDO
> 
>  
> 
> Secondo appuntamento
> 
> SABATO 15 DICEMBRE - ORE 19
> 
> “LA RICCA EREDITÀ DI UN TESTIMONE DELLA GRANDE STORIA”
> 
> SERATA IN RICORDO DI ROMANO CAGNONI
> 
> con PATRICIA FRANCESCHETTI CAGNONI, BRUNO SEGRE E FRANCO PAGETTI
> 
>  
> 
> INGRESSO GRATUITO
> 
> (fino ad esaurimento posti)
> 
>  
> 
> TI ASPETTIAMO!
> 
>  
> 
> Anche in diretta streaming su:
> 
> http://www.afipinternational.com/news/diretta-streaming/
> 
> 
> 
> Copyright 2018 Sprea  
> 
> SE NON DESIDERI PIU' RICEVERE LE NOSTRE NEWSLETTER PUOI CANCELLARTI CLICCANDO 
> QUI
> 
> Se pensi che questo messaggio possa essere spam, segnala abuso
> Questo messaggio e' stato inviato in ottemperanza al Decreto Legislativo 
> 196/03 e del Regolamento UE 2016 679 (GDPR) in quanto utente iscritto alle 
> newsletter di Sprea, su www.mailant.it, per disattivare la ricezione delle 
> newsletter clicca qui.Per visionare il regolamento sulla privacy clicca qui


Appuntamento con il nuovo ciclo di lectiones magistrales di AFIP International

2018-12-11 Thread Sprea Editori
Se non visualizzi correttamente questo messaggio, clicca qui: 
http://www.mailant.it/nl.aspx?idp=14715&idn=101034&cvp=0E2FA94E582CE1334891A9A307CD9E07B21F6098&idu=6421465&cvup=68F3E666774589740B41DF1132118C422AD451F1
  

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-11 Thread Antoine Beaupré
On 2018-12-10 17:44:51, Mike Gabriel wrote:
> Hi,
>
> I'd like to discuss the possible pathways for getting FreeRDP fixed in  
> Debian jessie LTS (and Debian stretch, too).
>
> Last week I talked to Bernhard Miklautz (one of the FreeRDP upsteam  
> maintainers and the actual packager of FreeRDPv2 in Debian).
>
> 1. Looking at fixing FreeRDP v1.1 in jessie / stretch
> -
>
> He sketched up the following pathway for getting freerdp (v1.1) fixed  
> in Debian jessie (and stretch):
>
>* Backport https://github.com/FreeRDP/FreeRDP/pull/4499
>  -> required for FreeRDP in jessie/stretch to be able to connect  
> to current RDP servers
> (not a security issue, but a functionality issue due to  
> Microsoft updates rolled out
> during Q1 / 2018).
>  -> estimated effort: 1-2h
>
>* CVE-2018-8785: not needed for jessie / stretch (code not present)
>
>* CVE-2018-8786,
>  CVE-2018-8789: estimated hours for all three: 1-2h
>
>* CVE-2018-8787: estimated hours: 1-2h
>* CVE-2018-8788: can be become quite an effort, estimated time: 2h++
>
>* CVE-2018-8784: not needed for jessie / stretch (code not present)
>
>
> While this sounds nice and feasible the underlying tone of investing  
> so much work into FreeRDP v1.1 was a different one.
>
> E.g. the fix for CVE-2018-8789 should be quick and simple. But the  
> surrounding code is buggy to a great extent, too.
>
> There have been so many stabilizing code fixes over the past 1-2 years.
>
>
> 2. Backporting FreeRDP v2 from buster to jessie and stretch
> 
>
> Another approach, with a more stable and usable result is backporting  
> FreeRDP v2 to jessie and stretch right away.
>
> Most people (I hope) are using freerdp2-x11 from stretch-backports  
> (plus remmina from stretch-bpo) on Debian stable these days (freerdp  
> 1.1 in stretch is broken with Windows RDP servers that are up-to-date  
> with their patch levels).
>
> libfreerdp-client1.1
>Reverse Depends: freerdp-x11 (>= 
> 1.1.0~git20140921.1.440916e+dfsg1-4+deb8u1)
>Reverse Depends: libfreerdp-dbg (=  
> 1.1.0~git20140921.1.440916e+dfsg1-4+deb8u1)
>Reverse Depends: libfreerdp-dev (=  
> 1.1.0~git20140921.1.440916e+dfsg1-4+deb8u1)
>Reverse Depends: libguac-client-rdp0 (>= 0.8.3-1+b2)
>Reverse Depends: libxfreerdp-client1.1 (>=  
> 1.1.0~git20140921.1.440916e+dfsg1-4+deb8u1)
>Reverse Depends: remmina-plugin-rdp (>= 1.1.1-2)
>Reverse Depends: vlc (>= 2.2.7-1~deb8u1)
> freerdp-x11
>Reverse Depends: freerdp-x11-dbg (=  
> 1.1.0~git20140921.1.440916e+dfsg1-4+deb8u1)
>Reverse Depends: ltsp-client (5.5.4-4)
>
> So the plan could be this:
>
>- rebuild freerdp (v1.1) as a shared libs package only, drop  
> freerdp-x11 (which
>  contains the command line tool)
>
>- backport freerdp2 from Debian unstable to jessie/stretch
>- backport remmina from Debian unstable to jessie/stretch
>- rebuild vlc in jessie (and possibly stretch, too) without RDP support
>- ltsp-client: adapt command line syntax to new FreeRDP2 cli style

That sounds like a large change, especially about dropping RDP support
from VLC... Do we have any idea about how VLC uses RDP and how many of
our users expect that to work in the first place? How about changes in
remmima?

>- libguac-client-rdp0: leave as is... Guacamole upstream still believes in
>  FreeRDP v1.1 shared lib API...

"Believes"? I don't understand this point...

> Summary
> ---
>
> Before going any deeper into this, I'd love to get some feedback from  
> the LTS and the security team about the proposed strategies. Are there  
> other possible pathways to go? If so, please share yours.
>
> The FreeRDP v1.1 backporting work (8-10 hours) would have to be  
> outsourced to ThinCast in Austria (where most FreeRDP upstream devs  
> work these days).

I don't know of any other pathways, but from what I understand we have
some extra hours to spare, so we could allow ourselves such an expense
to keep jessie ... "stable". :)

A.
-- 
Dans vos mensonges de pierre
Vous gaspillez le soleil
- Gilles Vigneault