Re: CERT Advisory CA-2002-05 Multiple Vulnerabilities in PHP fileupload

2002-02-28 Thread Andrew Suffield
n, for people doing serious security setups. The normal solution in debian is to backport a fix to stable. I see php.org has a patch for php 4.0.6, this can probably be backported to 4.0.3/4.0.5 fairly easily. -- .''`. ** Debian GNU/Linux ** | Andrew Suffield : :' : http://

Re: CERT Advisory CA-2002-05 Multiple Vulnerabilities in PHP fileupload

2002-02-28 Thread Andrew Suffield
a solution, for people doing serious security setups. The normal solution in debian is to backport a fix to stable. I see php.org has a patch for php 4.0.6, this can probably be backported to 4.0.3/4.0.5 fairly easily. -- .''`. ** Debian GNU/Linux ** | Andrew Suffield : :' : http://

Re: dpkg-buildpackage (-rfakeroot) leaves setuid binaries

2002-01-22 Thread Andrew Suffield
d when it's become generally accepted, propose an amendment to policy. -- .''`. ** Debian GNU/Linux ** | Andrew Suffield : :' : http://www.debian.org/ | Dept. of Computing, `. `' | Imperial College, `- -><- | London, UK

Re: dpkg-buildpackage (-rfakeroot) leaves setuid binaries

2002-01-22 Thread Andrew Suffield
d when it's become generally accepted, propose an amendment to policy. -- .''`. ** Debian GNU/Linux ** | Andrew Suffield : :' : http://www.debian.org/ | Dept. of Computing, `. `' | Imperial College, `- -><- | London, U

Re: buffer overflow in /bin/gzip?

2001-11-21 Thread Andrew Suffield
(dst, src, len); > dst[len] = '\0'; Or use your own version of strncpy() which behaves more sensibly. This is my preference. -- .''`. ** Debian GNU/Linux ** | Andrew Suffield : :' : http://www.debian.org/ | Dept. of Computing, `. `'

Re: buffer overflow in /bin/gzip?

2001-11-21 Thread Andrew Suffield
(dst, src, len); > dst[len] = '\0'; Or use your own version of strncpy() which behaves more sensibly. This is my preference. -- .''`. ** Debian GNU/Linux ** | Andrew Suffield : :' : http://www.debian.org/ | Dept. of Computing, `. `'

Re: Does Debian need to enforce a better Security policy for packages?

2001-10-23 Thread Andrew Suffield
easy. You are trying to put a fence around the moon. -- .''`. ** Debian GNU/Linux ** | Andrew Suffield : :' : | Dept. of Computing, `. `' | Imperial College, `-http://www.debian.org/ | London, UK

Re: Does Debian need to enforce a better Security policy for packages?

2001-10-23 Thread Andrew Suffield
easy. You are trying to put a fence around the moon. -- .''`. ** Debian GNU/Linux ** | Andrew Suffield : :' : | Dept. of Computing, `. `' | Imperial College, `-http://www.debian.org/ | London, UK -- To UNSUBSCRIB