about bash and Debian Lenny

2014-10-01 Thread Nikolay Hristov
Hello there, I know that this is outdated debian release and it is in the archives but I still have 6 servers running Lenny and I don't want to upgrade them to newer versions for several reasons. Any chance that we will get official debian package for Lenny? I'm sure that I'm not the only one

Re: about bash and Debian Lenny

2014-10-01 Thread Alberto Gonzalez Iniesta
On Wed, Oct 01, 2014 at 02:28:17PM +0300, Nikolay Hristov wrote: Hello there, I know that this is outdated debian release and it is in the archives but I still have 6 servers running Lenny and I don't want to upgrade them to newer versions for several reasons. Any chance that we will get

Re: about bash and Debian Lenny

2014-10-01 Thread Izak Burger
I made lenny packages for my machines. I could share them if you want? On Wed, Oct 1, 2014 at 1:28 PM, Nikolay Hristov ge...@stemo.bg wrote: Hello there, I know that this is outdated debian release and it is in the archives but I still have 6 servers running Lenny and I don't want to upgrade

Re: about bash and Debian Lenny

2014-10-01 Thread Nikolay Hristov
On 10/01/2014 02:37 PM, Izak Burger wrote: I made lenny packages for my machines. I could share them if you want? On Wed, Oct 1, 2014 at 1:28 PM, Nikolay Hristov ge...@stemo.bg mailto:ge...@stemo.bg wrote: Hello there, I know that this is outdated debian release and it is in the

Re: about bash and Debian Lenny

2014-10-01 Thread David Dejaeghere
What part of: Debian GNU/Linux 5.0 has been superseded by Debian 6.0 (squeeze). Security updates have been discontinued as of February 6th, 2012. http://www.debian.org/releases/lenny/index.en.html , didnt you understand? :) There are much more security issues than shellshock alone with Debian

Re: about bash and Debian Lenny

2014-10-01 Thread Nikolay Hristov
On 10/01/2014 02:59 PM, David Dejaeghere wrote: What part of: Debian GNU/Linux 5.0 has been superseded by Debian 6.0 (squeeze). Security updates have been discontinued as of February 6th, 2012. http://www.debian.org/releases/lenny/index.en.html , didnt you understand? :) There are much more

Re: about bash and Debian Lenny

2014-10-01 Thread Izak Burger
Still, when someone offers their help there really is no need to play a smart ass as you did. The only thing you might achieve doing that is a) direct rebuttals (my e-mail) and b) mild propositions to build patched packages yourself. Admittedly I didn't read the email as properly as I

Re: about bash and Debian Lenny

2014-10-01 Thread Nikolay Hristov
On 10/01/2014 02:58 PM, Konstantin Khomoutov wrote: On Wed, 1 Oct 2014 14:45:55 +0300 Nikolay Hristov ge...@stemo.bg wrote: I made lenny packages for my machines. I could share them if you want? [...] Which part of I don't want to use deb packages from different sources because I cannot

Re: about bash and Debian Lenny

2014-10-01 Thread Konstantin Khomoutov
On Wed, 1 Oct 2014 14:45:55 +0300 Nikolay Hristov ge...@stemo.bg wrote: I made lenny packages for my machines. I could share them if you want? [...] Which part of I don't want to use deb packages from different sources because I cannot trust them you didnt understand? ;-) Still, when

Re: about bash and Debian Lenny

2014-10-01 Thread David Dejaeghere
With Qmail exposed and being an attack vector I would advice to build your own updated bash package. You wont get official security updates. 2014-10-01 14:06 GMT+02:00 Nikolay Hristov ge...@stemo.bg: On 10/01/2014 02:58 PM, Konstantin Khomoutov wrote: On Wed, 1 Oct 2014 14:45:55 +0300

Re: about bash and Debian Lenny

2014-10-01 Thread David Dejaeghere
Also about not thrusting people, you are sending to this list with your company email address and tell everyone here you have an exploitable qmail setup running. Be carefull with the information you make public. Regards, David 2014-10-01 14:17 GMT+02:00 David Dejaeghere

Re: about bash and Debian Lenny

2014-10-01 Thread Yves-Alexis Perez
On mer., 2014-10-01 at 15:03 +0300, Nikolay Hristov wrote: In other words we need security update for older debian distributions. That won't happen. -- Yves-Alexis Perez - Debian Security signature.asc Description: This is a digitally signed message part

Re: about bash and Debian Lenny

2014-10-01 Thread Jens Schüßler
* Nikolay Hristov ge...@stemo.bg wrote: On 10/01/2014 02:58 PM, Konstantin Khomoutov wrote: On Wed, 1 Oct 2014 14:45:55 +0300 Nikolay Hristov ge...@stemo.bg wrote: I made lenny packages for my machines. I could share them if you want? [...] Which part of I don't want to use deb packages

Re: about bash and Debian Lenny

2014-10-01 Thread Paul Wise
On Wed, Oct 1, 2014 at 7:28 PM, Nikolay Hristov wrote: I still have 6 servers running Lenny and I don't want to upgrade them to newer versions for several reasons. Could you mention these on the list? If so perhaps we can provide some advice. If not perhaps you can find a Debian consultant who

Re: about bash and Debian Lenny

2014-10-01 Thread Carlos Alberto Lopez Perez
On 01/10/14 13:28, Nikolay Hristov wrote: Hello there, I know that this is outdated debian release and it is in the archives but I still have 6 servers running Lenny and I don't want to upgrade them to newer versions for several reasons. Any chance that we will get official debian package

Re: about bash and Debian Lenny

2014-10-01 Thread Jann Horn
On Wed, Oct 01, 2014 at 02:28:17PM +0300, Nikolay Hristov wrote: Hello there, I know that this is outdated debian release and it is in the archives but I still have 6 servers running Lenny and I don't want to upgrade them to newer versions for several reasons. Any chance that we will get

Re: about bash and Debian Lenny

2014-10-01 Thread Paul Wise
On Thu, Oct 2, 2014 at 1:37 AM, Jann Horn wrote: You're doing this the wrong way - as others have already said, upgrade your server to a supported release. Based on our off-list discussions, Nikolay has valid reasons for not upgrading. -- bye, pabs https://wiki.debian.org/PaulWise -- To

External check

2014-10-01 Thread Raphael Geissert
CVE-2014-3607: RESERVED CVE-2014-7230: missing from list CVE-2014-7231: missing from list -- The output might be a bit terse, but the above ids are known elsewhere, check the references in the tracker. The second part indicates the status of that id in the tracker at the moment the script was