Re: 17 updates for Etch?!?!¡!¡¡111oneo nelevenoneone

2008-07-27 Thread Alexander Reichle-Schmehl
Hi! Cyril Brulebois schrieb: >> WTF?!?!? Were all those apps + kernel updated today? > Point release, see [1]. I guess the announcement is on its way. Might be > sent once most architectures have all packages built. > 1. http://www.philkern.de/weblog/en/debian/etch_4.0r4.html Sorry for the in

Re: 17 updates for Etch?!?!¡!¡¡111oneo nelevenoneone

2008-07-27 Thread Alexander Reichle-Schmehl
Hi! Alexander Reichle-Schmehl schrieb: > Sorry for the inconvenience. The announcement will be sent out within > 30 minutes; still waiting for final approval for one part. Here it is: http://www.debian.org/News/2008/20080726 or http://lists.debian.org/debian-announce/2008/msg

Re: apt-get not upgrading kernel

2008-09-12 Thread Alexander Reichle-Schmehl
Hi! * Kheng Teong Goh <[EMAIL PROTECTED]> [080912 04:21]: > I have 2 system on slicehost running debian. apt-get update and apt-get > upgrade has not been upgrading my kernel. It has been upgrading other > packages. > > Kernel remains as : 2.6.18-xen #1 SMP Tue Feb 12 06:40:50 UTC 2008 x86_64

Re: apt-get not upgrading kernel

2008-09-12 Thread Alexander Reichle-Schmehl
Hi! * Simon Valiquette <[EMAIL PROTECTED]> [080912 11:14]: [ Disclaimer: I'm not a member of the security team nor of our kernel team, so I don't know any details ] >> The latest kernel related DSA (1636) only affected the 2.6.24 >> kernel shipped with Etch-and-a-half. > I can see that CV

Re: apt-get not upgrading kernel

2008-09-12 Thread Alexander Reichle-Schmehl
Hi! * Alexander Reichle-Schmehl <[EMAIL PROTECTED]> [080912 10:49]: > > I have 2 system on slicehost running debian. apt-get update and apt-get > > upgrade has not been upgrading my kernel. It has been upgrading other > > packages. > > > > Kernel remains as

Etch 4.0r5 in preparation

2008-10-23 Thread Alexander Reichle-Schmehl
Hi! During the next hours you might notice some package updates and wonder, why there hasn't been any security advisory for these updates. That's because the next stable point release Debian GNU/Linux 4.0r5 "Etch" is currently spread to the mirrors. A proper announcement will be send out soon to

Re: Recommend good IDS? was Re: /dev/shm/r?

2009-06-04 Thread Alexander Reichle-Schmehl
Hi! john schrieb: > I'd be interested to hear some recommendations for IDS to run on > internet facing servers. Especially from the point of view of ease of > installation, ease of maintenance, quality of the tool, and ability to > have it deliver really useful information to the admin. I've used

Re: bastille in lenny

2009-07-09 Thread Alexander Reichle-Schmehl
Hi! Matt Richardson schrieb: > Running Bastille in Lenny revealed that Bastille won't run in Lenny, > it complains about an unsupported OS version. The latest version in > the supported OS list is 4.0 (/usr/lib/Bastille/API.pm). There were > some bug reports filed on dating back to January and i

Re: On publishing/announcing end of security support

2010-01-20 Thread Alexander Reichle-Schmehl
Hi! Simon Paillard schrieb: >> Security Support for Debian GNU/Linux 4.0 to be discontinued on >> February 15th > The website doesn't support publishing package-less DSA (or it will > looks *very* ugly). > > Though such announce could be sent to both debian-announce and > -security-announce, I g

Upcoming Lenny point release; don't panic

2010-01-29 Thread Alexander Reichle-Schmehl
Hi! Our stable release managers are working on a new point release (5.0.4 if I'm not mistaken) which should hit the mirrors this weekend. So don't panic if you see updates in stable without security advisory. A proper announcement of the changes will be published as soon as the point release has

AW: Re: jedit_4.3.1+dfsg-1_amd64.changes REJECTED

2010-04-05 Thread Alexander Reichle-Schmehl
(Sorry for the TOFU Mail; send from my Handheld.) Hi! Again such a package will only be accepted, if the security team gave their okay, as it still might not solve their problem completely: If a security problem is found and fixed in bsh, does jedit need to be recompiled, too, to pick up the s

Re: jedit_4.3.1+dfsg-1_amd64.changes REJECTED

2010-04-09 Thread Alexander Reichle-Schmehl
Hi! Moritz Muehlenhoff schrieb: bsh code copies don't strike me as a security-relevant overhead, personally I don't have any objections. If it's fine with you, it's okay with us. We don't like it (the archive is already big enough without yet another code copy), but we'll accept it. Best

Re: New Lenny Point Release

2010-12-01 Thread Alexander Reichle-Schmehl
Hi! Am 01.12.2010 12:24, schrieb Gerfried Fuchs: >> The link "press release" on http://debian.org/releases/stable/ points to >> http://debian.org/News/2009/20090214 while that should be >> http://debian.org/News/2010/20101127 [..] > I'll be thinking of how to reword the release page itself to ma

Re: some feedback about security from the user's point of view

2011-01-24 Thread Alexander Reichle-Schmehl
Hi! Am 23.01.2011 18:34, schrieb AK: > 2) Regarding MD5, while indeed it has been broken, is it not sufficient > for simple checksumming purposes? [..] Having said that, I am all for the use > of > SHA256 or better in all newer examples/hashes, I cannot stress how > strongly I agree, even for th

Re: some feedback about security from the user's point of view

2011-01-24 Thread Alexander Reichle-Schmehl
Hi! Am 24.01.2011 14:34, schrieb Naja Melan: >> I think this can be a start: >> http://www.google.pl/search?sourceid=chrome&ie=UTF-8&q=site:debian.com+md5 [..] > should be .org I think Yes, but that still return some 96'000 documents. Even limiting it to english documents of the site www.debian

Re: sun-java6 updates for {old,}stable?

2011-03-09 Thread Alexander Reichle-Schmehl
Hi! * Jonathan Wiltshire [110309 09:38]: > The packages are non-free, so they do not get security support. They will > be in the next point release for Squeeze in a few weeks [1]. See <1299615077.9459.397.ca...@hathi.jungle.funky-badger.org> ; Squeeze point release planed for 19th of March. Be

Re: [SECURITY] [DSA 2418-1] postgresql-8.4 security update

2012-02-27 Thread Alexander Reichle-Schmehl
Hi! Am 27.02.2012 18:43, schrieb Moritz Muehlenhoff: > - > Debian Security Advisory DSA-2418-1 secur...@debian.org > http://www.debian.org/security/Moritz Muehlenhoff > February 27, 20