Bug#701200: ferm

2017-08-04 Thread Alexander Wirt
On Fri, 04 Aug 2017, Adam McKenna wrote: > Alright I guess I'll have to take this to debian-security then, this may > even warrant a CVE I completly disagree, but lets see what -security says. Alex

Bug#701200: ferm

2017-08-04 Thread Adam McKenna
Alright I guess I'll have to take this to debian-security then, this may even warrant a CVE On Fri, Aug 4, 2017 at 9:23 AM Alexander Wirt wrote: > On Fri, 04 Aug 2017, Adam McKenna wrote: > > > That makes no sense, if that's the case then why is a default ruleset > > provided for ipv4 but not ip

Bug#701200: ferm

2017-08-04 Thread Alexander Wirt
On Fri, 04 Aug 2017, Adam McKenna wrote: > That makes no sense, if that's the case then why is a default ruleset > provided for ipv4 but not ipv6? > > More and more systems are running ipv6 these days and ferm users may not > even know their systems are exposed in this way. Thats why I fixed it,

Bug#701200: ferm

2017-08-04 Thread Adam McKenna
That makes no sense, if that's the case then why is a default ruleset provided for ipv4 but not ipv6? More and more systems are running ipv6 these days and ferm users may not even know their systems are exposed in this way. On Fri, Aug 4, 2017 at 9:16 AM Alexander Wirt wrote: > fixed 701200 2.4

Processed: Re: Bug#701200: ferm

2017-08-04 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > fixed 701200 2.4-1 Bug #701200 {Done: Alexander Wirt } [ferm] default rules should be applied to both IPv4 and IPv6 Ignoring request to alter fixed versions of bug #701200 to the same values previously set > thanks Stopping processing here. Ple

Bug#701200: ferm

2017-08-04 Thread Alexander Wirt
fixed 701200 2.4-1 thanks On Fri, 04 Aug 2017, Adam McKenna wrote: > tag 701200 security > > This is not just a bug, this is a gaping security hole. The default > configuration is wide open on ipv6. > > Please add, at a minimum, the following default rules for ipv6: This was fixed in unstable