[Full-disclosure] [SECURITY] [DSA 1118-1] New Mozilla packages fix several vulnerabilities

2006-07-22 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1118-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 22nd, 2006

[Full-disclosure] [SECURITY] [DSA 1119-1] New hiki packages fix denial of service

2006-07-22 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1119-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 22nd, 2006

Accepted dpkg-multicd 0.21 (source all)

2006-07-22 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sat, 22 Jul 2006 19:39:15 +0200 Source: dpkg-multicd Binary: dpkg-multicd Architecture: source all Version: 0.21 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL

Re: Unknown format character in info file (',,,s') (was: CIA)

2006-07-22 Thread Martin Schulze
Florian Ernst wrote: However, this warning remains: | cvs commit: warning: commitinfo line contains no format strings: | /cvs/webwml/CVSROOT/commit_prep2 -r | Appending defaults ( %r/%p %s), but please be aware that this usage is | deprecated. It doesn't stop any commits, though, so for

Re: Unknown format character in info file (',,,s') (was: CIA)

2006-07-22 Thread Martin Schulze
Martin Schulze wrote: Florian Ernst wrote: However, this warning remains: | cvs commit: warning: commitinfo line contains no format strings: | /cvs/webwml/CVSROOT/commit_prep2 -r | Appending defaults ( %r/%p %s), but please be aware that this usage is | deprecated. It doesn't stop

[SECURITY] [DSA 1118-1] New Mozilla packages fix several vulnerabilities

2006-07-22 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1118-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 22nd, 2006

[SECURITY] [DSA 1119-1] New hiki packages fix denial of service

2006-07-22 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1119-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 22nd, 2006

[Full-disclosure] [SECURITY] [DSA 1114-1] New hashcash packages fix arbitrary code execution

2006-07-21 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1114-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 21st, 2006

[Full-disclosure] [SECURITY] [DSA 1115-1] New GnuPG2 packages fix denial of service

2006-07-21 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1115-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 21st, 2006

Re: Unknown format character in info file (',,,s') (was: CIA)

2006-07-21 Thread Martin Schulze
Florian Ernst wrote: | cvs commit: warning: commitinfo line contains no format strings: | /cvs/webwml/CVSROOT/commit_prep2 -r | Appending defaults ( %r/%p %s), but please be aware that this usage is | deprecated. | [... the above repeated once per file ...] |

[SECURITY] [DSA 1115-1] New GnuPG2 packages fix denial of service

2006-07-21 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1115-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 21st, 2006

[SECURITY] [DSA 1114-1] New hashcash packages fix arbitrary code execution

2006-07-21 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1114-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 21st, 2006

Re: Using the SSL snakeoil certificate

2006-07-20 Thread Martin Schulze
Jaldhar H. Vyas wrote: In bug #376146, Martin Pitt wrote: In an effort to clean up the SSL certificate mess on Ubuntu servers, we recently converted all our supported Server packages to make use of the ssl-cert package instead of creating a package-specific self-signed SSL certificate.

Re: Using the SSL snakeoil certificate

2006-07-20 Thread Martin Schulze
(please copy debian-devel, feel free to bounce my mail there after you've done so, for others to be able to comment as well). Klaus Ethgen wrote: Am Do den 20. Jul 2006 um 11:24 schrieb Martin Schulze: [one cert for all services] I believe that this is a good idea, however, I would like

Re: Warning during CVS commit

2006-07-19 Thread Martin Schulze
Frans Pop wrote: Hi all, Today I got the following warning during a commit of changes to the debian-installer section of the website. Someone know what this is about? cvs commit: warning: Set to use deprecated info format strings. Establish compatibility with the new info file format

Re: CIA

2006-07-19 Thread Martin Schulze
Wouter Verhelst wrote: Hi, The WWW repository used to have CIA messages, but that seems to be gone now since the compromise. I assume this is a known issue, but I wanted to mention it just in case it isn't. We need to find out what %{,,,s} is with the new CVS and UseNewInfoFmtStrings=yes

Re: Debian at Wizards of OS?

2006-07-19 Thread Martin Schulze
Martin Schulze wrote: Nico Golde wrote: The Wizards of Open Source congress will take please this year too in Berlin. 14.-16. September 2006 in the Columbia Hall The WOS is an international conference mainly about free and open source software, free media, free hardware and about

Debian Weekly News - July 18th, 2006

2006-07-18 Thread Martin Schulze
--- Debian Weekly News http://www.debian.org/News/weekly/2006/29/ Debian Weekly News - July 18th, 2006 --- Welcome to this year's 29th issue of DWN, the

Bug#378631: haxe: Description improvement

2006-07-17 Thread Martin Schulze
Package: haxe Version: current Severity: minor - Description: Web programming languge generating Flash, AJAX or Neko + Description: Web programming language generating Flash, AJAX or Neko Regards, Joey -- Whenever you meet yourself you're in a time loop or in front of a mirror.

Debian Weekly News - July 11th, 2006

2006-07-11 Thread Martin Schulze
--- Debian Weekly News http://www.debian.org/News/weekly/2006/28/ Debian Weekly News - July 11th, 2006 --- Welcome to this year's 28th issue of DWN, the

[Full-disclosure] [SECURITY] [DSA 1106-1] New ppp packages fix privilege escalation

2006-07-10 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1106-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 10th, 2006

[Full-disclosure] [SECURITY] [DSA 1107-1] New GnuPG packages fix denial of service

2006-07-10 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1107-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 10th, 2006

[SECURITY] [DSA 1106-1] New ppp packages fix privilege escalation

2006-07-10 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1106-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 10th, 2006

Re: Debian at Wizards of OS?

2006-07-10 Thread Martin Schulze
Moin! Nico Golde wrote: The Wizards of Open Source congress will take please this year too in Berlin. 14.-16. September 2006 in the Columbia Hall The WOS is an international conference mainly about free and open source software, free media, free hardware and about the free and open

Bug#375617: Patch

2006-07-09 Thread Martin Schulze
Attached is a patch that simply changes the pathname. Regards, Joey -- Testing? What's that? If it compiles, it is good, if it boots up, it is perfect. Please always Cc to me when replying to me on the lists. diff -u -p -Nr --exclude CVS orig/spread-3.17.2/session.c

Bug#356939: Security fix for shadow in sarge (#356939)

2006-07-09 Thread Martin Schulze
Christian Perrier wrote: As a consequence, I hereby ask the security team to DROP the processing of the 4.0.3-31sarge6 version you have. As you wish, packages deleted. Regards, Joey -- Testing? What's that? If it compiles, it is good, if it boots up, it is perfect. Please always Cc

Bug#356939: Security fix for shadow in sarge (#356939)

2006-07-09 Thread Martin Schulze
Christian Perrier wrote: As a consequence, I hereby ask the security team to DROP the processing of the 4.0.3-31sarge6 version you have. As you wish, packages deleted. Regards, Joey -- Testing? What's that? If it compiles, it is good, if it boots up, it is perfect. Please always Cc

Bug#356939: Security fix for shadow in sarge (#356939)

2006-07-09 Thread Martin Schulze
Christian Perrier wrote: As a consequence, I hereby ask the security team to DROP the processing of the 4.0.3-31sarge6 version you have. As you wish, packages deleted. Regards, Joey -- Testing? What's that? If it compiles, it is good, if it boots up, it is perfect. Please always Cc

Re: Security fix for shadow in sarge (#356939)

2006-07-09 Thread Martin Schulze
Christian Perrier wrote: As a consequence, I hereby ask the security team to DROP the processing of the 4.0.3-31sarge6 version you have. As you wish, packages deleted. Regards, Joey -- Testing? What's that? If it compiles, it is good, if it boots up, it is perfect. Please always Cc

[Full-disclosure] [SECURITY] [DSA 1105-1] New xine-lib packages fix denial of service

2006-07-07 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1105-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 7th, 2006

Bug#372719: regression in FreeType security fix for DSA-1095

2006-07-07 Thread Martin Schulze
Hi! Steve Langasek wrote: As mentioned earlier this month, a regression was found in the freetype 2.1.7-2.5 package uploaded for DSA-1095 which caused applications to crash with division-by-zero errors. I've prepared a maintainer upload to fix this regression using the patch from bug

Bug#372719: regression in FreeType security fix for DSA-1095

2006-07-07 Thread Martin Schulze
Steve Langasek wrote: On Mon, Jun 26, 2006 at 08:36:07AM +0100, Steve Kemp wrote: On Sun, Jun 25, 2006 at 03:09:51PM -0700, Steve Langasek wrote: As mentioned earlier this month, a regression was found in the freetype 2.1.7-2.5 package uploaded for DSA-1095 which caused applications to

[SECURITY] [DSA 1105-1] New xine-lib packages fix denial of service

2006-07-07 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1105-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 7th, 2006

Bug#372719: regression in FreeType security fix for DSA-1095

2006-07-07 Thread Martin Schulze
Hi! Steve Langasek wrote: As mentioned earlier this month, a regression was found in the freetype 2.1.7-2.5 package uploaded for DSA-1095 which caused applications to crash with division-by-zero errors. I've prepared a maintainer upload to fix this regression using the patch from bug

Bug#372719: regression in FreeType security fix for DSA-1095

2006-07-07 Thread Martin Schulze
Steve Langasek wrote: On Mon, Jun 26, 2006 at 08:36:07AM +0100, Steve Kemp wrote: On Sun, Jun 25, 2006 at 03:09:51PM -0700, Steve Langasek wrote: As mentioned earlier this month, a regression was found in the freetype 2.1.7-2.5 package uploaded for DSA-1095 which caused applications to

[Full-disclosure] [SECURITY] [DSA 1104-2] New OpenOffice.org packages fix arbitrary code execution

2006-07-06 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1104-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 6th, 2006

[EMAIL PROTECTED]: Debian project at ApacheCon?]

2006-07-06 Thread Martin Schulze
Is somebody interested in representing Debian at the Apache Con 06 in Austin? Regards, Joey - Forwarded message from Lars Eilebrecht [EMAIL PROTECTED] - Date: Fri, 16 Jun 2006 03:35:54 +0200 From: Lars Eilebrecht [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Debian project

[SECURITY] [DSA 1104-2] New OpenOffice.org packages fix arbitrary code execution

2006-07-06 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1104-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 6th, 2006

Debian Weekly News - July 4th, 2006

2006-07-04 Thread Martin Schulze
--- Debian Weekly News http://www.debian.org/News/weekly/2006/27/ Debian Weekly News - July 4th, 2006 --- Welcome to this year's 27th issue of DWN, the

Re: Transfer Maintainership From MIA Maintainer

2006-07-03 Thread Martin Schulze
Jason Self wrote: The listed maintainers for the Webmin package (http://packages.debian.org/stable/admin/webmin) and the associated packages like webmin-core, Usermin, etc. are MIA. They are not fixing bugs or responding anymore. The package has been removed from etch and sid, alias testing

Re: These new diffs are great, but...

2006-06-30 Thread Martin Schulze
Steinar H. Gunderson wrote: On Thu, Jun 29, 2006 at 08:35:41PM +0200, martin f krafft wrote: Not really. pdiff's mainly reduce download size for low bandwidth connections. file:// is pretty high bandwidth, you won't notice the difference. I usually notice the difference -- the other way.

Re: BADSIG verifying s.d.o Release file

2006-06-30 Thread Martin Schulze
martin f krafft wrote: I've been seeing this a bunch in the past few weeks. Just making sure you know about it, and maybe someone knows what's going on: W: GPG error: http://security.debian.org stable/updates Release: The following signatures were invalid: BADSIG 010908312D230C5F Debian

[SECURITY] [DSA 1104-1] New OpenOffice.org packages fix several vulnerabilities

2006-06-30 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1104-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 30th, 2006

[Full-disclosure] [SECURITY] [DSA 1104-1] New OpenOffice.org packages fix several vulnerabilities

2006-06-29 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1104-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 30th, 2006

Accepted thuban 1.0.1-1.1 (source i386)

2006-06-27 Thread Martin Schulze
-By: Martin Schulze [EMAIL PROTECTED] Description: thuban - an interactive geographic data viewer Closes: 368060 Changes: thuban (1.0.1-1.1) unstable; urgency=medium . * Non-maintainer upload * Built against wxWidgets 2.4.5.1 (closes: Bug#368060) * Added a conflict against python-wxgtk2.6

[DebianGIS-dev] Fixed in NMU of thuban 1.0.1-1.1

2006-06-27 Thread Martin Schulze
: 1.0.1-1.1 Distribution: unstable Urgency: medium Maintainer: Debian GIS Project pkg-grass-devel@lists.alioth.debian.org Changed-By: Martin Schulze [EMAIL PROTECTED] Description: thuban - an interactive geographic data viewer Closes: 368060 Changes: thuban (1.0.1-1.1) unstable; urgency=medium

Re: sending debian-private postings to gmail

2006-06-26 Thread Martin Schulze
Domenico Andreoli wrote: it's nice to have your personal gobal searchable mailing list archive, where you can really find anything you have ever received. Even though it is nice, it's also problematic to scatter around private and hence sensitive (at least temporarily sensitive) information on

Re: RSS Feed for DWN?

2006-06-26 Thread Martin Schulze
MJ Ray wrote: Martin Schulze [EMAIL PROTECTED] Two examples are here: http://people.debian.org/~joey/dwn.en.rdf http://people.debian.org/~joey/dwn.de.rdf These are 404 Not Found at this time. The RDF files are now generated automatically if there is a version of the current issue

Re: RSS Feed for DWN?

2006-06-25 Thread Martin Schulze
Matt Kraai wrote: On Wed, Jun 21, 2006 at 10:31:33AM +0200, Martin Schulze wrote: I've seen that somebody has included the RSS feed for DWN by damog in Planet Debian. I really wonder why this still hasn't been integrated in www.debian.org. I found a mail from March on this subject. Hence

Bug#368060: packaging for etch ok -

2006-06-22 Thread Martin Schulze
Here are packages that I would upload if you don't object. http://people.debian.org/~joey/NMU/thuban/ Regards, Joey -- Given enough thrust pigs will fly, but it's not necessarily a good idea. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble?

Bug#374577: mimms: patch to fix many buffer overflows vulnerability

2006-06-22 Thread Martin Schulze
Anon Sricharoenchai wrote: Package: mimms Version: 0.0.9-1 Severity: grave Justification: user security hole Tags: security patch According to the patch attached in this report, it has many possible buffer overflows. For example, - memcpy(buf, data, length) without bounding the limit of

Re: RSS Feed for DWN?

2006-06-22 Thread Martin Schulze
MJ Ray wrote: Martin Schulze [EMAIL PROTECTED] Two examples are here: http://people.debian.org/~joey/dwn.en.rdf http://people.debian.org/~joey/dwn.de.rdf These are 404 Not Found at this time. You're too slow, their lifetime ended this morning. Regards, Joey -- Given enough

Bug#368060: packaging for etch ok -

2006-06-22 Thread Martin Schulze
Here are packages that I would upload if you don't object. http://people.debian.org/~joey/NMU/thuban/ Regards, Joey -- Given enough thrust pigs will fly, but it's not necessarily a good idea. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble?

Bug#374577: mimms: patch to fix many buffer overflows vulnerability

2006-06-22 Thread Martin Schulze
Anon Sricharoenchai wrote: Package: mimms Version: 0.0.9-1 Severity: grave Justification: user security hole Tags: security patch According to the patch attached in this report, it has many possible buffer overflows. For example, - memcpy(buf, data, length) without bounding the limit of

[DebianGIS-dev] Bug#368060: packaging for etch ok -

2006-06-22 Thread Martin Schulze
Here are packages that I would upload if you don't object. http://people.debian.org/~joey/NMU/thuban/ Regards, Joey -- Given enough thrust pigs will fly, but it's not necessarily a good idea. ___ Pkg-grass-devel mailing list

RSS Feed for DWN?

2006-06-21 Thread Martin Schulze
Martin Schulze [EMAIL PROTECTED] # # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation; either version 2 of the License, or # (at your option) any later version. # # This program

Re: RSS Feed for DWN?

2006-06-21 Thread Martin Schulze
Matt Kraai wrote: On Wed, Jun 21, 2006 at 10:31:33AM +0200, Martin Schulze wrote: I've seen that somebody has included the RSS feed for DWN by damog in Planet Debian. I really wonder why this still hasn't been integrated in www.debian.org. I found a mail from March on this subject. Hence

Accepted manpages 2.34-1 (source all)

2006-06-20 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Tue, 20 Jun 2006 19:23:19 +0200 Source: manpages Binary: manpages manpages-dev Architecture: source all Version: 2.34-1 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze

Re: Call for a new DPL mediation ... This will be the only thread i will reply to in the next time about this issue.

2006-06-20 Thread Martin Schulze
Benjamin Seidenberg wrote: AIUI (please, correct me if I am wrong) the D-I repository is hosted on svn.d.o, a machine belonging to the debian project. I don't see why the DPL would have authority over the mailing lists (hosted on a debian machine and maintained by the list admins) but not the

Debian Weekly News - June 20th, 2006

2006-06-20 Thread Martin Schulze
--- Debian Weekly News http://www.debian.org/News/weekly/2006/25/ Debian Weekly News - June 20th, 2006 --- Welcome to this year's 25th issue of DWN, the

Debian Day at FrOSCon

2006-06-20 Thread Martin Schulze
During this year's FrOSCon the Debian project will run a one-day conference on Saturday, June 24th aimed at users and people interested in the structure of Debian. The Debian project will also run a booth and demonstrate the Debian distribution. FrOSCon is a two day conference on Free Software

Re: Debian Day at FrOSCon

2006-06-20 Thread Martin Schulze
Christian Perrier wrote: Quoting Martin Schulze ([EMAIL PROTECTED]): During this year's FrOSCon the Debian project will run a one-day conference on Saturday, June 24th aimed at users and people interested From the speakers list and the language used, I can guess this is quite likely

Bug#374388: Changing default Accept: list

2006-06-19 Thread Martin Schulze
Package: lynx Version: 2.8.5-2sarge2 Severity: wishlist When I try to view http://www.debian.org/events/2006/0624-froscon content negotiation is in place. Lynx requests a file of type text/html, [..], text/*. However, text/calendar and text/html are available on www.debian.org and Apache seems

Bug#373913: [EMAIL PROTECTED]: CVE-2006-3081 assigned to MySQL str_to_date() DoS]

2006-06-19 Thread Martin Schulze
FYI Regards, Joey - Forwarded message from Steven M. Christey [EMAIL PROTECTED] - == Name: CVE-2006-3081 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3081 Reference: BUGTRAQ:20060614 MySQL DoS

Bug#373913: [EMAIL PROTECTED]: CVE-2006-3081 assigned to MySQL str_to_date() DoS]

2006-06-19 Thread Martin Schulze
FYI Regards, Joey - Forwarded message from Steven M. Christey [EMAIL PROTECTED] - == Name: CVE-2006-3081 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3081 Reference: BUGTRAQ:20060614 MySQL DoS

Bug#374296: Changing default Accept: list

2006-06-18 Thread Martin Schulze
Martin Schulze wrote: It may be a good idea to adjust the default accept_media setting (which will result in the Accept: HTTP header) a little bit: - accept_media text/*, image/*, application/*, message/*, audio/* + accept_media text/html, text/plain, text/comma-separated-values, text/xml

Apache delivering the wrong file

2006-06-18 Thread Martin Schulze
Hmm... With the addition of calendar (ics) files I noticed a changed behaviour in the Apache on www.debian.org. When I view the .../events/ page with lynx or w3m and try to follow one of the events links, the calendar file is displayed instead of the rendered HTML file. The problem is that lynx

Re: Apache delivering the wrong file

2006-06-18 Thread Martin Schulze
Richard Atterer wrote: Ah, the joys of Apache content negotiation... :-7 Well.. :) 4) AddType text/calendar;qs=0.9 .ics This is not well documented, but it works! (At least I know it does with Apache 2.) That's sufficient and even works with Apache 1.3. Wonderful! Do we have a

Re: Apache delivering the wrong file

2006-06-18 Thread Martin Schulze
Richard Atterer wrote: On Sun, Jun 18, 2006 at 04:57:01PM +0200, Martin Schulze wrote: That's sufficient and even works with Apache 1.3. Wonderful! Do we have a framework to tell the mirrors that they should alter their webserver configuration? Not to my knowledge. You could put

[SECURITY] [DSA 1100-1] New wv2 packages fix integer overflow

2006-06-15 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1100-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 15th, 2006

Re: CVE-2006-2314: debian dovecot package vulnerable. (fwd)

2006-06-15 Thread Martin Schulze
martin f krafft wrote: I tend to agree with Joey on the issue, though I do think it's not very nice that the postgresql security upgrade breaks other packages. But going via stable-proposed-updates seems like the right path. Have you talked to the stable release team? Maybe they'd be

Debian Weekly News - June 13th, 2006

2006-06-13 Thread Martin Schulze
--- Debian Weekly News http://www.debian.org/News/weekly/2006/24/ Debian Weekly News - June 13th, 2006 --- Welcome to this year's 24th issue of DWN, the

[SECURITY] [DSA 1096-1] New webcalendar packages fix arbitrary code execution

2006-06-13 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1096-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 13th, 2006

[Full-disclosure] [SECURITY] [DSA 1096-1] New webcalendar packages fix arbitrary code execution

2006-06-12 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1096-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 13th, 2006

Accepted gerstensaft 0.2-7 (source i386)

2006-06-10 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sat, 10 Jun 2006 14:45:17 +0200 Source: gerstensaft Binary: gerstensaft Architecture: source i386 Version: 0.2-7 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL

[SECURITY] [DSA 1095-1] New freetype packages fix several vulnerabilities

2006-06-10 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1095-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 10th, 2006

[Full-disclosure] [SECURITY] [DSA 1095-1] New freetype packages fix several vulnerabilities

2006-06-09 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1095-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 10th, 2006

[Full-disclosure] [SECURITY] [DSA 1091-1] New TIFF packages fix arbitrary code execution

2006-06-08 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1091-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 8th, 2006

[Full-disclosure] [SECURITY] [DSA 1092-1] New MySQL 4.1 packages fix SQL injection

2006-06-08 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1092-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 8th, 2006

[Full-disclosure] [SECURITY] [DSA 1093-1] New xine-ui packages fix denial of service

2006-06-08 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1093-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 8th, 2006

Accepted sendfile 2.1b-1 (source i386)

2006-06-08 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Thu, 8 Jun 2006 07:23:58 +0200 Source: sendfile Binary: sendfile Architecture: source i386 Version: 2.1b-1 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL PROTECTED

Accepted manpages 2.33-2 (source all)

2006-06-08 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Thu, 8 Jun 2006 08:18:50 +0200 Source: manpages Binary: manpages manpages-dev Architecture: source all Version: 2.33-2 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze

Bug#326606: sendfile: receive fails to bounce

2006-06-08 Thread Martin Schulze
Ulli Horlacher wrote: However, receive reacts like this: $ receive -ba [EMAIL PROTECTED] %receive-Warning: file [EMAIL PROTECTED] not found Bug in the receive man-page (*). The correct syntax is: receive -ab [EMAIL PROTECTED] (The argument for option -b must be the recipients

Bug#372172: CVE-2006-2230: Denial of service in xine-ui

2006-06-08 Thread Martin Schulze
@@ -1,3 +1,12 @@ +xine-ui (0.99.3-1sarge1) stable-security; urgency=high + + * Non-maintainer upload by the Security Team + * Corrected call to report() and printf() to fix format string +vulnerabilities [src/xitk/main.c, src/xitk/xine-toolkit/xitk.c, +CVE-2006-2230] + + -- Martin Schulze [EMAIL

[SECURITY] [DSA 1093-1] New xine-ui packages fix denial of service

2006-06-08 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1093-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 8th, 2006

[SECURITY] [DSA 1091-1] New TIFF packages fix arbitrary code execution

2006-06-08 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1091-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 8th, 2006

[SECURITY] [DSA 1092-1] New MySQL 4.1 packages fix SQL injection

2006-06-08 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1092-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 8th, 2006

Bug#372172: CVE-2006-2230: Denial of service in xine-ui

2006-06-08 Thread Martin Schulze
@@ -1,3 +1,12 @@ +xine-ui (0.99.3-1sarge1) stable-security; urgency=high + + * Non-maintainer upload by the Security Team + * Corrected call to report() and printf() to fix format string +vulnerabilities [src/xitk/main.c, src/xitk/xine-toolkit/xitk.c, +CVE-2006-2230] + + -- Martin Schulze [EMAIL

[Full-disclosure] [SECURITY] [DSA 1090-1] New spamassassin packages fix remote command execution

2006-06-06 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1090-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 6th, 2006

Bug#370668: Spelling errors in tmpreaper

2006-06-06 Thread Martin Schulze
Package: tmpreaper Version: 1.6.6 Severity: minor /usr/share/doc/tmpreaper/README.security.gz: - Now let is sit, suspended, for x days. Tmpreaper then removes the + Now let it sit, suspended, for x days. Tmpreaper then removes the - limit it to a certian smaller class of victim programs,

Re: sarge3 kernel build r3

2006-06-06 Thread Martin Schulze
dann frazier wrote: I saw some questions on irc about the sarge3 kernel build r3... zobel it's just, i actualy wanted to release sarge r3 with sarge2 kernels. now i get told sarge3-kernels are already prepared, which disapoints me a bit, as noone told the stable release team

Debian Weekly News - June 6th, 2006

2006-06-06 Thread Martin Schulze
--- Debian Weekly News http://www.debian.org/News/weekly/2006/23/ Debian Weekly News - June 6th, 2006 --- Welcome to this year's 23rd issue of DWN, the

[SECURITY] [DSA 1090-1] New spamassassin packages fix remote command execution

2006-06-06 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1090-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 6th, 2006

Re: [sigc] Accumulators

2006-06-05 Thread Martin Schulze
You are right - this look like a bug! Most likely, in signal.h.m4, definition of struct signal_emit$1, line: typedef internal::slot_iterator_bufself_type slot_iterator_buf_type; should read: typedef internal::slot_iterator_bufself_type,T_return slot_iterator_buf_type; Could you file a bug

Accepted manpages 2.33-1 (source all)

2006-06-04 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sun, 4 Jun 2006 08:27:46 +0200 Source: manpages Binary: manpages manpages-dev Architecture: source all Version: 2.33-1 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze

Bug#368202: sarge: dia: CVE-2006-2480 and CVE-2006-2453: format string vulnerability

2006-06-04 Thread Martin Schulze
Roland Stigge wrote: Hi, besides the upload to unstable, I've backported the upstream patch for #368202. See attachment. Feel free to upload if appropriate. We don't consider it approriate unless you provide us with an attack vector, i.e. automatic processing of files from untrusted

Debian IRC Network moves to OFTC

2006-06-04 Thread Martin Schulze
The Debian Projecthttp://www.debian.org/ Debian IRC Network moves to OFTC[EMAIL PROTECTED] June 4th, 2006 http://www.debian.org/News/2006/20060604

[SECURITY] [DSA 1087-1] New PostgreSQL packages fix encoding vulnerabilities

2006-06-04 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1087-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 3rd, 2006

[SECURITY] [DSA 1088-1] New centericq packages fix arbitrary code execution

2006-06-04 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1088-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 3rd, 2006

[SECURITY] [DSA 1089-1] New freeradius packages fix arbitrary code execution

2006-06-04 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1089-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 3rd, 2006

<    5   6   7   8   9   10   11   12   13   14   >