Re: [SECURITY] p7zip: CVE-2015-1038

2016-02-10 Thread Achim Gratz
Tony Kelman writes: > Thanks for the help Corinna. > > I don't have anything for sourceware or cygwin.com in > ~/.ssh/known_hosts, should I? Recently the default configuration has been changed to only have hashes in that file. You could change it back or use ssh management commands to remove the

RE: [SECURITY] p7zip: CVE-2015-1038

2016-02-10 Thread Tony Kelman
> What means "NMU"? Sorry, that's a Debian term for "non-maintainer upload." I don't know if we ever do those in Cygwin? > Recently the default configuration has been changed to only have hashes > in that file. You could change it back or use ssh management commands > to remove the existing

Re: How to get upload rights for existing packages

2016-02-10 Thread Corinna Vinschen
On Feb 9 20:26, Achim Gratz wrote: > Corinna Vinschen writes: > >> Sure, but co-maintenance _is_ possible, with each of the maintainers > >> having their own separate upload area. > > > > Yes, but Michael still has to become maintainer, even if co-maintainer. > > True, in the absence of anything

Re: [SECURITY] p7zip: CVE-2015-1038

2016-02-10 Thread Corinna Vinschen
On Feb 9 14:48, Tony Kelman wrote: > >> I don't have anything for sourceware or cygwin.com in > >> ~/.ssh/known_hosts, should I? > > > > In theory, yes. It's usually collected the first time you connect to > > the host. The idea is to have a known key to compare the host against > > to disallow