Re: [SECURITY] [DSA 1565-1] New Linux 2.6.18 packages fix several vulnerabilities

2008-05-13 Thread Mike Gerber
* Stephen Gran schrieb: I also do some rummaging around to figure out what the meta package is currently depending on, so that I know what vesion Debian currently considers newest, then compare that to /proc/version. That only works for etch and newer kernel images, though, so I think I'll

Re: [SECURITY] [DSA 1565-1] New Linux 2.6.18 packages fix several vulnerabilities

2008-05-03 Thread Mike Gerber
Hi, Package: linux-2.6 Vulnerability : several vulnerabilities Problem type : local Debian-specific: no CVE Id(s) : CVE-2007-6694 CVE-2008-0007 CVE-2008-1294 CVE-2008-1375 [...] For the stable distribution (etch), this problem has been fixed in version

Re: WTF: Debian security, ex. Linux kernel vulnerabilities

2005-09-20 Thread Mike Gerber
Andreas Barth schrieb/wrote/a écrit/escribió: Well, the basic problem with mirrors is: * How can we be sure that all mirrors are synced _very_ fast? We will probably get more negative feedback if some mirrors are delayed by more than 10 minutes (and some of our normal mirrors are _way_

Re: Security risks due to packages that are no longer part of Debian?

2005-07-12 Thread Mike Gerber
A tool which lists all packages which are no longer downloadable from any APT source would be more helpful, I think. Does it already exist? I have a slighty inefficient script for that. I believe there are better ways to do what listallpackages does, unknown to the author of the script back

Re: murphy in sbl.spamhaus.org

2004-11-26 Thread Mike Gerber
George Georgalis schrieb/wrote/a écrit/escribió: On Fri, Nov 26, 2004 at 10:57:31AM +0100, Florian Weimer wrote: * Christian Storch: What about greylisting depending on results of e.g. SA? Only above a limit of scores from SA greylisting would be become active. This is very impolite because