Re: [SECURITY] [DSA 1548-1] New xpdf packages fix arbitrary code exitution

2008-05-05 Thread Lasse Kliemann
* Message by -Devin Carraway- from Thu 2008-04-17: > Package: xpdf > Vulnerability : multiple > Problem type : local (remote) > Debian-specific: no > CVE Id(s) : CVE-2008-1693 [...] > For the unstable distribution (sid), these problems were fixed in > version 3.02-1.2. Is that r

Re: [SECURITY] [DSA 1569-1] New cacti packages fix multiple vulnerabilities

2008-05-05 Thread sean finney
hi guys, as i alerted you on IRC, this update renders cacti unusable. see: #479618 and #479621 . it's pretty clear that the upload was done without any testing, and furthermore without first submitting a bug on the cacti package. tsk tsk :) sean On Monday 05 May 2008 05:58:54 pm T

Re: [SECURITY] [DSA 1565-1] New Linux 2.6.18 packages fix several vulnerabilities

2008-05-05 Thread Peter Palfrader
On Mon, 05 May 2008, Peter Palfrader wrote: > On Mon, 05 May 2008, Bernd Eckenfels wrote: > > > In article <[EMAIL PROTECTED]> you wrote: > > > Apropos. Is there a way to get that information from a vmlinuz file on > > > disk? Without booting it, that is. > > > > Interesting enough my (somewha

Re: [SECURITY] [DSA 1565-1] New Linux 2.6.18 packages fix several vulnerabilities

2008-05-05 Thread Peter Palfrader
On Mon, 05 May 2008, Bernd Eckenfels wrote: > In article <[EMAIL PROTECTED]> you wrote: > > Apropos. Is there a way to get that information from a vmlinuz file on > > disk? Without booting it, that is. > > Interesting enough my (somewhat older) file command does only print "x86 > boot sector",

Re: [SECURITY] [DSA 1550-1] New suphp packages fix local privilege escalation

2008-05-05 Thread Nicolas Boullis
Hi, Adrian Minta wrote: > > Try apache2-mpm-itk. Is better than suphp IMHO ! I saw it, but its description reads "Please note that this MPM is highly experimental, and is not from the same tree as the other MPMs.", so I did not consider using it on a production server. For what it's worth, liba

Re: apt-get may accept inconsistent data

2008-05-05 Thread Bjørn Mork
Stefan Tichy <[EMAIL PROTECTED]> writes: > On Mon, May 05, 2008 at 01:03:33AM +0200, Goswin von Brederlow wrote: >> I ment what Release file. Because the etch security one does have the >> md5sums of Packages in it. > > This has been modified too and the md5sum listed for the packages > file has ch

Re: apt-get may accept inconsistent data

2008-05-05 Thread Stefan Tichy
On Mon, May 05, 2008 at 01:03:33AM +0200, Goswin von Brederlow wrote: > I ment what Release file. Because the etch security one does have the > md5sums of Packages in it. This has been modified too and the md5sum listed for the packages file has changed. > > apt-get sends a http GET request for P

Re: [SECURITY] [DSA 1565-1] New Linux 2.6.18 packages fix several vulnerabilities

2008-05-05 Thread Stephen Gran
This one time, at band camp, Peter Palfrader said: > debian.org kernel packages don't however. Which makes it not exactly > suiteable for a nagios check for "is the running kernel the one on the > fileystem". This one time, at band camp, Noah Meyerhans said: > I compare the ctime of the kernel im