Re: [SECURITY] [DSA 1292-1] New qt4-x11 packages fix cross-site scripting vulnerability

2007-05-15 Thread Noah Meyerhans
On Wed, May 16, 2007 at 09:03:12AM +1000, Andrew Vaughan wrote: > > Package: qt4-x11 > > > For the stable distribution (etch), this problem has been fixed in > > version 4.2.1-2etch1 > > > Etch shipped with 4.2.1-2+b1 packages. > > $ dpkg --compare-versions "4.2.1-2+b1" ">>" "4.2.1-2etc

Re: [SECURITY] [DSA 1291-1] New samba packages fix multiple vulnerabilities

2007-05-15 Thread Geoff Crompton
Noah Meyerhans wrote: > > Debian Security Advisory DSA-1291-1[EMAIL PROTECTED] > http://www.debian.org/security/ Noah Meyerhans > May 15, 2007 > -

Re: [SECURITY] [DSA 1292-1] New qt4-x11 packages fix cross-site scripting vulnerability

2007-05-15 Thread Andrew Vaughan
On Wednesday 16 May 2007 08:22, Noah Meyerhans wrote: > > Package: qt4-x11 > For the stable distribution (etch), this problem has been fixed in > version 4.2.1-2etch1 > Etch shipped with 4.2.1-2+b1 packages. $ dpkg --compare-versions "4.2.1-2+b1" ">>" "4.2.1-2etch1" && echo yes yes Per

Re: [SECURITY] [DSA 1291-1] New samba packages fix multiple vulnerabilities

2007-05-15 Thread Roberto C . Sánchez
[not subscribed to -security, so please keep me on the CC] On Tue, May 15, 2007 at 07:34:53PM +0200, Noah Meyerhans wrote: > > For the stable distribution (etch), these problems have been fixed in > version 3.0.24-6etch1 > > For the testing and unstable distributions (lenny and sid, > respective

Re: security mirror out of date: 128.101.240.212

2007-05-15 Thread Philip Hands
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Philip Hands wrote: > Tomas Nykung wrote: >> On Mon, May 14, 2007 at 10:04:46AM +0200, martin f krafft wrote: >>> FYI: >>> >>> < weinholt> one of the security.debian.org mirrors is out of date. >>> 128.101.240.212 has a /debian-security/dists/etch/upda

Re: debian.org DNSs allow unrestricted zone transfers

2007-05-15 Thread Giacomo A. Catenazzi
martin f krafft wrote: also sprach Giacomo A. Catenazzi <[EMAIL PROTECTED]> [2007.05.15.1646 +0200]: the theory: zone transfer of a DNS gives internal information about structure and IPs of internal machines. my theory: that information should be public, or at least if it were, the network sh

Re: debian.org DNSs allow unrestricted zone transfers

2007-05-15 Thread martin f krafft
also sprach Giacomo A. Catenazzi <[EMAIL PROTECTED]> [2007.05.15.1646 +0200]: > the theory: zone transfer of a DNS gives internal information about > structure and IPs of internal machines. my theory: that information should be public, or at least if it were, the network should not be unsafer bec

Re: debian.org DNSs allow unrestricted zone transfers

2007-05-15 Thread Giacomo A. Catenazzi
martin f krafft wrote: also sprach Abel Martín <[EMAIL PROTECTED]> [2007.05.15.1356 +0200]: I thought zone transfers should only be possible between DNSs which have records for the same domain, so why are debian.org DNSs (raff, rietz, klecker) allowing zone transfers? Maybe I'm paranoid, but I t

Re: debian.org DNSs allow unrestricted zone transfers

2007-05-15 Thread martin f krafft
also sprach Abel Martín <[EMAIL PROTECTED]> [2007.05.15.1356 +0200]: > I thought zone transfers should only be possible between DNSs > which have records for the same domain, so why are debian.org DNSs > (raff, rietz, klecker) allowing zone transfers? Maybe I'm > paranoid, but I think there are sec

debian.org DNSs allow unrestricted zone transfers

2007-05-15 Thread Abel Martín
Hi, I thought zone transfers should only be possible between DNSs which have records for the same domain, so why are debian.org DNSs (raff, rietz, klecker) allowing zone transfers? Maybe I'm paranoid, but I think there are security issues related to this, including the possibility of suffering Do

Re: security mirror out of date: 128.101.240.212

2007-05-15 Thread Tomas Nykung
On Mon, May 14, 2007 at 11:19:32PM +0200, Martin Zobel-Helas wrote: > > no. Bad karma. I like this explanation the most :) This would explain a lot... Funny thing is that today when i run "host security.debian.org" i get alternating results exactly as it should be, so today it looks like rerunni