Re: serious bug / 1.7.8-1sarge7.2.1_i386 / URGENT

2006-09-08 Thread Von Wolher
Alexander Sack wrote:
> On Fri, Sep 08, 2006 at 07:08:43PM +0200, Von Wolher wrote:
> 
>>PS:
>>
>>Alexander, i also have your update/fix installed and every message where
>>i said to enigmail to sign + encrypt went only signed out in the
>>cleartext. :(
>>
>>I would greatly appreciate it if you can see what's going on.
>>
> 
> 
> I cannot reproduce the problem with fixed versions of thunderbird and
> mozilla ... it encrypts properly here.
> 
>  - Alexander
> 

My apologies, it does work, i had a setting enabled which said never to
display key selection and for certain recipients it was needed to select.

Thanks for the fast reaction anyway bud !!!


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Re: serious bug / 1.7.8-1sarge7.2.1_i386 / URGENT

2006-09-08 Thread Von Wolher
PS:

Alexander, i also have your update/fix installed and every message where
i said to enigmail to sign + encrypt went only signed out in the
cleartext. :(

I would greatly appreciate it if you can see what's going on.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Re: serious bug / 1.7.8-1sarge7.2.1_i386 / URGENT

2006-09-08 Thread Von Wolher
Dale Amon wrote:
> On Tue, Sep 05, 2006 at 01:04:40AM +0200, Von Wolher wrote:
> 
>>Thank you very much for the lightspeed reaction and fix !!!
>>I'll set those extra lines in the sources.list of a few general use
>>boxes which also run pure debian sarge and will keep you updated in case
>>an updated doesn't workout.
> 
> 
> Perhaps I am not the only one who has seen problems
> in recent firefox updates then... I can reliably crash
> my firefox browser simply by going to google maps. It
> starts loading the map... and then falls over.
> 




guys, where do i start...i just noticed today that since that update
which messed up mozilla mail+news/enigmail all messages which should
have been signed AND encrypted got only signed !!!

Which means everything went in the cleartext !!!

I'm a bit speechless here to what more to say :(

Can some one check this ?


Here i include also the message of our previous communication:



==

On Mon, Sep 04, 2006 at 07:31:30PM +0200, Von Wolher wrote:

>> Hello Kitame,
>>
>> I'm sorry to approach you like this but we got a very urgent situation
>> which was caused by the latest update for mozilla-*. This update messed
>> up enigmail completely. We got now 5 systems showing the exact
>> behaviour. They use Mozilla 1.7.8 (latest sarge) and enigmail (latest
>> sarge). Enigmail doesn't show any keys anymore in the key management
>> window and some options might be missing from the key menu too.
>>
>> We checked with gpg on the commandline and luckily everything was there
>> in the rings and also working fine on the commandline.
>>
>> These boxes run the official sarge release, no backports or anything
>> exotic on them, pure sarge debian. Please let me know how to solve this
>> problem since our users can't work on the commandline.
>>
>> To be sure, it happened with the latest update:
>>
>> [SECURITY] [DSA 1160-1] New Mozilla packages fix several vulnerabilities
>>
>> after installing that with apt-get enigmail stopped working properly.
>>


As you can still use enigmail core features, aka encrypt/decrypt and
sign/verify it has yet to be decided if we will roll-out an updated
package for this issue. In any case, if we push a dedicated update for
this, it will take some days until all architectures finished the new
build.

To give you instant cure - if you are using i386 - there will be a fix
in my security preview archive [1] in approx. one hour from now
(Version: 2:1.7.8-1sarge7.2.2).


FWIW, we need more volunteers (pure desktop sarge users) that help
testing mozilla updates before they get rolled out in order to prevent
bugs like this to slip through in future. For sarge we completely rely on
the help of our community to do QA which is not provided by the mozilla
project anymore - they have abandoned security support for versions
shipped in sarge.

To help, just keep the security archive lines [1] in your
sources.list and upgrade regularly. Better monitor my blog (see sig)
to get informed if a new security update is about to land. If there is
a new security update, keep your eyes open for new bugs and report
them to me.

Thanks,

==


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Re: serious bug / 1.7.8-1sarge7.2.1_i386 / URGENT

2006-09-08 Thread Alexander Sack
On Fri, Sep 08, 2006 at 07:08:43PM +0200, Von Wolher wrote:
> PS:
> 
> Alexander, i also have your update/fix installed and every message where
> i said to enigmail to sign + encrypt went only signed out in the
> cleartext. :(
> 
> I would greatly appreciate it if you can see what's going on.
> 

I cannot reproduce the problem with fixed versions of thunderbird and
mozilla ... it encrypts properly here.

 - Alexander

-- 
 GPG messages preferred.   |  .''`.  ** Debian GNU/Linux **
 Alexander Sack| : :' :  The  universal
 [EMAIL PROTECTED]   | `. `'  Operating System
 http://www.asoftsite.org  |   `-http://www.debian.org


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Re: Franco Parisi/Cassa_Risparmio_Bolzano_Spa/ITè assente dall'ufficio.

2006-09-08 Thread Fibu


Mit freundlichen Grüssen

Ehrhard Müller KG
Finanzbuchhaltung
i.A. Melanie Hermani
Fon   : 06721/972043
Fax   : 06721/972039
E-Mail: [EMAIL PROTECTED]
Web   : mueller-kg.de


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Re: Firefox on testing hijacked by http://www.megago.com/l/?

2006-09-08 Thread Torsten Sadowski
Am Donnerstag, 7. September 2006 21:30 schrieben Sie:
> * Torsten Sadowski:
> > I did a grep over ~/.firefox and voila, there is the culprit:
> >
> > default/8nfma0b5.slt/prefs.js:user_pref("sessionsaver.windows.session2",
> > "session2 997  901  1280  59  11  0  1
> > s0,,:0,,:0,,:0,,:0,,:0,,:-1,,:-1,,:-1,,:-1,,:-1,,:-1,, |i,,vvT |z1 |0
> > |0,0| http://www.megago.com/l/?  0");
>
> This is probably related to an extension called "Session Saver".  Have
> you instructed Firefox to install it?

Yes, Session Saver is definitely wanted. I just don't know how the megago 
entry got into it. I will look into it a bit more but if Session Saver is a 
security risk I will have to live without it.

Torsten


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Re: Too busy to go back to school,{} but need a University {}Degree{} to get ahead?

2006-09-08 Thread Bradly Stewart
Greetings Debian-security-request!!!
Absolutely are no mandatory tests, classes, books, or interviews !

Capture a_Bachelors, Masters., MBA, and Doctorate (PhD) diploma.

Achieve the assets and blessing_that comes with a.diploma !



Never anyone is pushed away



Anonymity made

Dial Us Whenever +1   (270)   81872   44
Good Anytime

















changes its place as a whole: but the growing thing changes its placewhereas, 
in so far as it is potentially 'flesh' only, it iscomes-to-be will have to 
come-to-be out of nothing. Although we haveof another, and the passing-away of 
one thing is always another'sapplies only to things which have 'position'. And 
'position' belongstimes. Nothing impossible will have resulted, though perhaps 
nobody inreason of this conflict is that each group is in fact stating a 
part,and Fire alike? And again, is the matter of each different? Or is it


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]