Re: [Cooker] security alert in syslkogd

2000-09-21 Thread Vincent Danen

On Thu Sep 21, 2000 at 02:46:24PM +0200, Guillaume Cottenceau wrote:

> Steve Fox <[EMAIL PROTECTED]> writes:
> 
> > Patti Wavinak wrote:
> > > 
> > > I received the security alert day before yesterday from Linux Mandrake
> > > Security Team :-)
> > > This is what it says
> > > 
> > 
> > 
> > A major kudos to whoever is in charge of the security stuff. I remember
> > a few months ago everyone (including myself) complaning about the slow
> > updates from MandrakeSoft. Now it seems that Mandrake is always one of
> > the first
> > 
> > Go Mandrake!!!
> 
> Yes, thanks to good work from Vincent Danen. Congrats to him on that.



Thanks, folks.  I appreciate the comments and I'm just happy that you
are happy.  =)  It means I'm doing my job... =)

-- 
[EMAIL PROTECTED], OpenPGP key available on www.keyserver.net
// Danen Consulting Serviceswww.danen.net, www.freezer-burn.org
// MandrakeSoft, Inc.   www.linux-mandrake.com
1024D/FE6F2AFD   88D8 0D23 8D4B 3407 5BD7  66F9 2043 D0E5 FE6F 2AFD

Current Linux uptime: 6 hours 5 minutes.




Re: [Cooker] security alert in syslkogd

2000-09-21 Thread Guillaume Cottenceau

Steve Fox <[EMAIL PROTECTED]> writes:

> Patti Wavinak wrote:
> > 
> > I received the security alert day before yesterday from Linux Mandrake
> > Security Team :-)
> > This is what it says
> > 
> 
> 
> A major kudos to whoever is in charge of the security stuff. I remember
> a few months ago everyone (including myself) complaning about the slow
> updates from MandrakeSoft. Now it seems that Mandrake is always one of
> the first
> 
> Go Mandrake!!!

Yes, thanks to good work from Vincent Danen. Congrats to him on that.



-- 
Guillaume Cottenceau -- Distribution Developer for MandrakeSoft
http://www.mandrakesoft.com/~gc/




Re: [Cooker] security alert in syslkogd

2000-09-20 Thread Steve Fox

Patti Wavinak wrote:
> 
> I received the security alert day before yesterday from Linux Mandrake
> Security Team :-)
> This is what it says
> 


A major kudos to whoever is in charge of the security stuff. I remember
a few months ago everyone (including myself) complaning about the slow
updates from MandrakeSoft. Now it seems that Mandrake is always one of
the first

Go Mandrake!!!

-- 

Steve Fox
http://k-lug.com




Re: [Cooker] security alert in syslkogd

2000-09-20 Thread Renaud

Guillaume Rousse a écrit :

> There has been a security alert for Debian about syslogkd, but i
> couldn't find the details. Is Mandrake also concerned ?

A patch for the current version (1.3) has been applied yesterday.
Version 1.4 has just been announced by the way, but I don't know
yet if it's affected.

Renaud






Re: [Cooker] security alert in syslkogd

2000-09-20 Thread Patti Wavinak


I received the security alert day before yesterday from Linux Mandrake 
Security Team :-) 
This is what it says



Linux-Mandrake Security Update Advisory


Package name: sysklogd
Date: September 18th, 2000
Advisory ID: MDKSA-2000:050

Affected versions: 6.0, 6.1, 7.0, 7.1


Problem Description:

A problem exists with the kernel logging daemon (klogd) in the sysklogd
package. A "format bug" makes klogd vulnerable to local root 
compromise, as well as the possibility for remote vulnerabilities under
certain circumstances, which are unprobable. There is also a more
probable semi-remote exploit via knfsd. This update provides a patched
version of klogd that fixes these vulnerabilities.


Please verify these md5 checksums of the updates prior to upgrading to
ensure the integrity of the downloaded package. You can do this by
running the md5sum program on the downloaded package by using
"md5sum package.rpm".

Linux-Mandrake 6.0:
f025156af9b4b9a296e5cee1cacae36f 6.0/RPMS/sysklogd-1.3.31-14mdk.i586.rpm
50792c33d6d1817b71d734711d6dcd4b 6.0/SRPMS/sysklogd-1.3.31-14mdk.src.rpm

Linux-Mandrake 6.1:
bc44efb4d6721cce0feb87535be14cd5 6.1/RPMS/sysklogd-1.3.31-14mdk.i586.rpm
50792c33d6d1817b71d734711d6dcd4b 6.1/SRPMS/sysklogd-1.3.31-14mdk.src.rpm

Linux-Mandrake 7.0:
4fb519ce5be0516113908140a26ad390 7.0/RPMS/sysklogd-1.3.31-15mdk.i586.rpm
36805570b5f2d7ae792573d45050332a 7.0/SRPMS/sysklogd-1.3.31-15mdk.src.rpm

Linux-Mandrake 7.1:
3d9416b240c87e58338d58361e5b289e 7.1/RPMS/sysklogd-1.3.31-15mdk.i586.rpm
36805570b5f2d7ae792573d45050332a 7.1/SRPMS/sysklogd-1.3.31-15mdk.src.rpm



I think this is what you are asking about?

Patti
Registered Linux User #184611

>>>>>>>>>>>>>>>>>> Original Message <<<<<<<<<<<<<<<<<<

On 9/20/00, 7:14:03 AM, Guillaume Rousse <[EMAIL PROTECTED]> 
wrote regarding [Cooker] security alert in syslkogd:


> There has been a security alert for Debian about syslogkd, but i
> couldn't find the details. Is Mandrake also concerned ?
> http://www.somelist.com/mail.php/132/view/714575
> --
> Guillaume Rousse
> Iremia - Université de la Réunion

> Plus petites unités de mesure
> - de longueur : le millimètre
> - de volume : le millilitre
> - d'intelligence : le militaire




[Cooker] security alert in syslkogd

2000-09-20 Thread Guillaume Rousse

There has been a security alert for Debian about syslogkd, but i
couldn't find the details. Is Mandrake also concerned ?
http://www.somelist.com/mail.php/132/view/714575
-- 
Guillaume Rousse
Iremia - Université de la Réunion

Plus petites unités de mesure 
- de longueur : le millimètre
- de volume : le millilitre
- d'intelligence : le militaire