Bug#702775: [Pkg-monitoring-maintainers] Bug#702775: ganglia: limiting security support

2013-05-28 Thread Daniel Pocock
On 28/05/13 10:33, Raphael Geissert wrote: > Hi, > > On 28 May 2013 10:12, Daniel Pocock wrote: >> Instead of adding the README.Debian.security file proposed in the >> earlier patch, I could add a README.security file upstream - the >> security issue is not Debian-specific. However, I will mentio

Bug#702775: [Pkg-monitoring-maintainers] Bug#702775: ganglia: limiting security support

2013-05-28 Thread Raphael Geissert
Hi, On 28 May 2013 10:12, Daniel Pocock wrote: > Instead of adding the README.Debian.security file proposed in the > earlier patch, I could add a README.security file upstream - the > security issue is not Debian-specific. However, I will mention in that > file that the Debian security team were

Bug#702775: [Pkg-monitoring-maintainers] Bug#702775: ganglia: limiting security support

2013-05-28 Thread Daniel Pocock
On 28/05/13 09:53, Raphael Geissert wrote: > Hi Daniel, > > > Although limiting security support is not something that the team > usually does, Ganglia is not the first package for which this decision > has been made. > It is done after a review of the package and its intended use. > > If you would

Bug#702775: [Pkg-monitoring-maintainers] Bug#702775: ganglia: limiting security support

2013-05-28 Thread Raphael Geissert
Hi Daniel, Although limiting security support is not something that the team usually does, Ganglia is not the first package for which this decision has been made. It is done after a review of the package and its intended use. If you would like to help change the status, please consider reviewing

Bug#702775: [Pkg-monitoring-maintainers] Bug#702775: ganglia: limiting security support

2013-05-27 Thread Daniel Pocock
On 27/05/13 18:41, Salvatore Bonaccorso wrote: > Hi Daniel, hi Stuart > > On Mon, Mar 11, 2013 at 11:34:49AM +0100, Raphael Geissert wrote: >> Package: ganglia >> Version: 3.3.8-1 >> Severity: grave >> Tags: security >> Control: clone -1 -2 >> Control: reassign -2 src:ganglia-web 3.5.2-1 >> X-Debb

Bug#702775: ganglia: limiting security support

2013-05-27 Thread Salvatore Bonaccorso
Hi Daniel, hi Stuart On Mon, Mar 11, 2013 at 11:34:49AM +0100, Raphael Geissert wrote: > Package: ganglia > Version: 3.3.8-1 > Severity: grave > Tags: security > Control: clone -1 -2 > Control: reassign -2 src:ganglia-web 3.5.2-1 > X-Debbugs-cc: t...@security.debian.org > > Hi again, > > Given t

Bug#702775: ganglia: limiting security support

2013-03-17 Thread Michael Gilbert
On Sun, Mar 17, 2013 at 3:04 PM, Michael Gilbert wrote: > Hi, I've uploaded an nmu to delayed/2 fixing this issue. Please see > attached patch. I've re-uploaded a new version to delayed/2 with a typo fixed. Please see revised attached patch. Best wishes, Mike ganglia.patch Description: Binary

Bug#702775: ganglia: limiting security support

2013-03-17 Thread Salvatore Bonaccorso
Hi Michael On Sun, Mar 17, 2013 at 03:04:15PM -0400, Michael Gilbert wrote: > control: tag -1 patch > > Hi, I've uploaded an nmu to delayed/2 fixing this issue. Please see > attached patch. Thank you for taking this. I read trough your proposed text looks good. Only one comment if you could ple

Bug#702775: ganglia: limiting security support

2013-03-17 Thread Michael Gilbert
control: tag -1 patch Hi, I've uploaded an nmu to delayed/2 fixing this issue. Please see attached patch. Best wishes, Mike ganglia.patch Description: Binary data

Bug#702775: ganglia: limiting security support

2013-03-15 Thread Julien Cristau
On Mon, Mar 11, 2013 at 11:34:49 +0100, Raphael Geissert wrote: > Given the recent issues in Ganglia's web frontend and a review of some > portions of the code we, as in the security team, have decided to > limit ganglia's security support to installations behind a trusted > HTTP zone. > Any vulne

Bug#702775: ganglia: limiting security support

2013-03-11 Thread Raphael Geissert
Package: ganglia Version: 3.3.8-1 Severity: grave Tags: security Control: clone -1 -2 Control: reassign -2 src:ganglia-web 3.5.2-1 X-Debbugs-cc: t...@security.debian.org Hi again, Given the recent issues in Ganglia's web frontend and a review of some portions of the code we, as in the security te