RE: [SECURITY] [DSA 3057-2] libxml2 regression update

2015-04-08 Thread Sebold, Charles
Darn it, we need this, but not during the day, just soon. We're using libxml2 to drive some important stuff, but it's all outgoing stuff, as far as I know. Charlie -Original Message- From: Salvatore Bonaccorso [mailto:car...@debian.org] Sent: Tuesday, April 07, 2015 1:59 PM To: debian

RE: [SECURITY] [DSA 3094-1] bind9 security update

2014-12-08 Thread Charles Stewart
Please disregard my prior message. It was directed to the incorrect recipients. My apologies for any inconvenience that might have been caused. -Original Message- From: Charles Stewart Sent: Monday, December 08, 2014 5:57 PM To: 'debian-security@lists.debian.org'; debia

RE: [SECURITY] [DSA 3094-1] bind9 security update

2014-12-08 Thread Charles Stewart
We don't run the bind9 server on production appliances, but we do pull in the bind9 client libs and tools, so that will need updating. -Original Message- From: Giuseppe Iuculano [mailto:iucul...@debian.org] Sent: Monday, December 08, 2014 4:43 PM To: debian-security-annou...@lists.debian

FW: CVE-2011-2147 is a dud, was Re:World writable pid and lock files.

2011-05-31 Thread Wergin, Charles
All, Looping in MITRE, as they are responsible for the assignment of CVEs. If it is determined this CVE has been assigned in error, updates to the NVD data feeds will be occur within 24 hours of MITRE updates. Thanks you, Chuck Wergin National Vulnerability Database nvd.nist.gov -Original M

Re: [Debian-med-packaging] Bug#496366: Bug#496366: Bug#496366: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Charles Plessy
a nice day, -- Charles Plessy Debian Med packaging team, Tsurumi, Kanagawa, Japan -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: [Debian-med-packaging] Bug#496366: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Charles Plessy
ers, and since mafft is a scientific software either used on personnal computers or on scientific workstations in trusted environments, can I ignore the bug for Lenny and work with Upsteam on a fix in the latest release? Have a nice day, -- Charles Plessy Debian Med packaging team, Tsurumi,

Bug#489678: tree-puzzle: Uses a local copy of libsprng.

2008-07-06 Thread Charles Plessy
libsprng2-dev Have a nice day, -- Charles Plessy, Debian-Med packaging team, Tsurumi, Kanagawa, Japan. -- System Information: Debian Release: lenny/sid APT prefers unstable APT policy: (500, 'unstable'), (500, 'testing') Architecture: powerpc (ppc64) Kernel: Linux 2.6.25-1-po

Re: JCE Code Signing Certificate

2005-10-12 Thread Charles Fry
rivate > key secret, publishing it still not be such a good idea. The key must be kept secret, otherwise it can't be trusted (i.e. people could maliciously modify the code, and then sign their modifications). How to best architect this into Debian is another question... Charles -- Substitut

Re: [SECURITY] [DSA 847-1] New dia packages fix arbitrary code execution

2005-10-08 Thread charles
Out of office until 17 Oct. Please contact [EMAIL PROTECTED] instead. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 846-1] New cpio packages fix several vulnerabilities

2005-10-07 Thread charles
Out of office until 17 Oct. Please contact [EMAIL PROTECTED] instead. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: JCE Code Signing Certificate

2005-10-04 Thread Charles Fry
chine. Further, due to what appears to be a Classpath bug, no free JVM that we do ship is able to pass all of the BouncyCastle regression tests (which is why BouncyCastle is currently in contrib). Does anyone from debian-java know how the free JVMs deal with security providers? Charles -- Always re

Re: JCE Code Signing Certificate

2005-10-04 Thread Charles Fry
rtificate, but instead of trusting them we want to build the code ourselves, which means that we in turn need to sign it ourselves. Does that clarify things a little? Charles -- From New York town To Pumpkin Holler Still Half a pound For half a dollar Burma-Shave No price increase http://burma-shav

Re: JCE Code Signing Certificate

2005-10-04 Thread Charles Fry
tests fail as the resulting jars need to be signed. Can someone please comment on how we should proceed to obtain a JCE Code Signing Certificate for Debian? thanks, Charles -Original Message- > From: Charles Fry <[EMAIL PROTECTED]> > Subject: JCE Code Signing Certificate > Da

JCE Code Signing Certificate

2005-09-30 Thread Charles Fry
aight-forward, as outlined in [4]. Having no previous experience with anything similar, I assume that this should be handled by the Security Team. I am hoping that someone on one of these lists will know the proper way to proceed from here. :-) cheers, Charles 1. http://www.bouncycastle.org/

GET CD AND DOWNLOADS, all software under $99-$15

2005-07-15 Thread Charles
Welcome to VIP Quality Software. http://bgvt.d2haguvoa5v2aed.recoolhhkld.info We think in generalities, but we live in detail. The most profound statements are often said in silence. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EM

Re: [d-security] Re: ssh vulnerability in the wild

2003-09-16 Thread Jean Charles Delepine
ody/updates and maybe one of the too should be renumbered. Jean Charles

Re: [d-security] Re: ssh vulnerability in the wild

2003-09-16 Thread Jean Charles Delepine
ody/updates and maybe one of the too should be renumbered. Jean Charles -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

RE: DHCP

2002-10-28 Thread Haines, Charles Allen
y, October 28, 2002 8:39 PM To: Haines, Charles Allen Cc: debian-security@lists.debian.org Subject: Re: DHCP Too bad there is no way to do a secure handshake w/ an id/password or even SecureID cards. Any way to make the same host name resolve to your IP irreguardless of what IP is allocted to y

RE: DHCP

2002-10-28 Thread Haines, Charles Allen
Well here at WPI, we have to register each and every MAC address that we wish to use on campus. If your MAC address isn't registered, you get no network. It works the same way with wireless. And to the best of my knowledge, DHCP is used. - Chuck Haines

RE: DHCP

2002-10-28 Thread Haines, Charles Allen
nt: Monday, October 28, 2002 8:39 PM To: Haines, Charles Allen Cc: [EMAIL PROTECTED] Subject: Re: DHCP Too bad there is no way to do a secure handshake w/ an id/password or even SecureID cards. Any way to make the same host name resolve to your IP irreguardless of what IP is allocted to your b

RE: DHCP

2002-10-28 Thread Haines, Charles Allen
Well here at WPI, we have to register each and every MAC address that we wish to use on campus. If your MAC address isn't registered, you get no network. It works the same way with wireless. And to the best of my knowledge, DHCP is used. - Chuck Haines

unsubscribe

2002-08-01 Thread Jean-Charles Preaux

Re: Updated Package List

2002-07-30 Thread Ahmed Charles
security part :-) ) Thanks allot Ahmed Charles - Original Message - From: "Gareth Bowker" <[EMAIL PROTECTED]> To: "Ahmed Charles" <[EMAIL PROTECTED]> Cc: "debian-security users" Sent: Tuesday, July 30, 2002 6:58 PM Subject: Re: Updated Package List

Updated Package List

2002-07-30 Thread Ahmed Charles
Good Day, Is there an updated package list that i can download manually so that my dselect is up-to-date? And if there is, where can i get it? Ahmed Charles

subscribe

2002-07-27 Thread Ahmed Charles
-- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: ssh x forwarding

2002-07-10 Thread Charles Mauch
s ? > > Alan. This was exactly the problem. Thanks for pointing it out. My firewall had a typo, permitting anything on the l0 interface instead of the lo interface, so the default rule was catching that traffic and blocking anything directed at localhost. Fixed and all is working fine

Security Updates Sources

2002-05-31 Thread Jean-Charles Preaux
Hello Just a little question :     is there a security updates sources for the woody release ? as : deb http://security.debian.org/ potato/updates main contrib non-free for the potato release ? Which i  can put in my /etc/apt/sources.list ? Thanks   Jean-Charles Preaux http

Security Updates Sources

2002-05-31 Thread Jean-Charles Preaux
Hello Just a little question :     is there a security updates sources for the woody release ? as : deb http://security.debian.org/ potato/updates main contrib non-free for the potato release ? Which i  can put in my /etc/apt/sources.list ? Thanks   Jean-Charles Preaux http

Re: answer from abuse@ptd.net

2001-09-03 Thread Charles Fulmer
bwuahahahahahaahhahahahahahhaahhahahahaahahhahahahahahaahahhahahahahahahahahaaa know how many copies of that i have on ptd account [EMAIL PROTECTED]

Re: answer from abuse@ptd.net

2001-09-02 Thread Charles Fulmer
bwuahahahahahaahhahahahahahhaahhahahahaahahhahahahahahaahahhahahahahahahahahaaa know how many copies of that i have on ptd account [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: secured bind default?

2001-07-12 Thread Charles Stevenson
and then `chroot' to the real filesystem. In my opinion a chroot jail for daemons is more effort than it's worth. Then again the alternative is not exactly cut and dry either. One would need to setup users and groups so that the service can run as a non-root user and still function corre

Re: secured bind default?

2001-07-12 Thread Charles Stevenson
and then `chroot' to the real filesystem. In my opinion a chroot jail for daemons is more effort than it's worth. Then again the alternative is not exactly cut and dry either. One would need to setup users and groups so that the service can run as a non-root user and still function corre

Re: secured bind default?

2001-07-12 Thread Charles Stevenson
ystem and then `chroot' to the real filesystem. In my opinion a chroot jail for daemons is more effort than it's worth. Then again the alternative is not exactly cut and dry either. One would need to setup users and groups so that the service can run as a non-root user and still function corre

Re: secured bind default?

2001-07-12 Thread Charles Stevenson
ystem and then `chroot' to the real filesystem. In my opinion a chroot jail for daemons is more effort than it's worth. Then again the alternative is not exactly cut and dry either. One would need to setup users and groups so that the service can run as a non-root user and still function corre

Re: Problems with root on network clients

2000-11-23 Thread Charles Goyard
x27;t have access to it, and thus can not use your network. Put keep in mind that boxes with physical access are a PITA to secure and keep secured. HTH. -- Charles

Re: Problems with root on network clients

2000-11-23 Thread Charles Goyard
x27;t have access to it, and thus can not use your network. Put keep in mind that boxes with physical access are a PITA to secure and keep secured. HTH. -- Charles -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]