Re: Testing needed: openjdk7 update for stable-security

2013-07-12 Thread Henri Salo
est regards > Georgi Why haven't you been happy with it? --- Henri Salo signature.asc Description: Digital signature

Re: cpe ids and package names

2012-11-14 Thread Henri Salo
d some kind of planning session to get ideas listed and somekind of roadmap. You can contact me directly if you want to give me tasks or share ideas etc, but I suggest we keep meeting in IRC some day. - Henri Salo ps. not yet Debian Developer -- To UNSUBSCRIBE, email to debian-securit

Re: Audit of Debian/Ubuntu for unfixed vulnerabilities because of embedded code copies

2012-09-29 Thread Henri Salo
n debian-security > and also drafted on http://wiki.debian.org/CPEtagPackagesDep >? > -- > Happy hacking > Petter Reinholdtsen Has there been any progress with this project? I am glad to help if there is something I can do? This is needed in my opinion. - Henri Salo -- To UNSUBSCRIB

Re: CVE-2011-1521 - fixed packet

2012-07-24 Thread Henri Salo
- python2.4 NOTE: http://bugs.python.org/issue11662 Bug #628455 is still marked as done. What is needed to be done exactly to get this issue closed permanently? :) - Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe"

Re: python 2.6.6 -> python 2.6.8

2012-06-25 Thread Henri Salo
For example http://security-tracker.debian.org/tracker/CVE-2012-1150 - Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/20120625114557.ga15...@lakka.kapsi.fi

Re: Vulnerable PHP version according to nessus

2011-12-28 Thread Henri Salo
/doc/manuals/securing-debian-howto/ - Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/20111228133153.ga15...@foo.fgeek.fi

Re: Bug#645881: critical update 29 available

2011-12-01 Thread Henri Salo
tes for squeeze, but judging by my > past performance, it will take a while. > > If someone else wants to work on these updates, I'll gladly share what > I've learnt about the packaging. I am happy to help in any way I can, but I have no Debian-hat nor status. Is ther

gdb: CVE-2011-4355 arbitrary code execution via .debug_gdb_scripts

2011-11-28 Thread Henri Salo
http://seclists.org/oss-sec/2011/q4/424 Is some package of Debian affected? Best regards, Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.

www.debian.org: Broken links on http://www.debian.org/doc/manuals/securing-debian-howto/ch12.en.html

2011-08-04 Thread Henri Salo
Package: www.debian.org Severity: normal *** Please type your report below this line *** 12.1.3: Part: "for example, the Common Criteria." Link: http://niap.nist.gov/cc-scheme/st/ 12.3.15: 1) Part: "Security Contact key (key ID 0x363CCD95)." Link: http://pgpkeys.pca.dfn.de:11371/pks/lookup?searc

Broken links in web-page

2011-07-28 Thread Henri Salo
n also be held upon the debian-audit mailing list, just be careful not to make it obvious which program contains the flaw." http://shellcode.org/mailman/listinfo/debian-audit says 404. Best regards, Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.o

Re: libpng CVE-2006-7244/CVE-2009-5063

2011-07-24 Thread Henri Salo
On Sun, Jul 24, 2011 at 04:54:41PM +0200, Moritz Mühlenhoff wrote: > Henri Salo schrieb: > > There is two open vulnerabilities in libpng 1.2.27-2+lenny4 as you can see > > from: > > > > http://security-tracker.debian.org/tracker/source-package/libpng > > > &

libpng CVE-2006-7244/CVE-2009-5063

2011-07-24 Thread Henri Salo
urity impact is unimportant.", but I think these aren't unimportant as you can see from here: http://www.openwall.com/lists/oss-security/2011/03/22/7 http://www.openwall.com/lists/oss-security/2011/03/28/6 Is there a plan to fix these issues? Should I create a bug-report? Best rega

CVE-identifier for dovecot wrong Mail dir permissions

2010-09-16 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Description: dovecot wrong Mail dir permissions Temporary name: TEMP-000-005740 CVE-identifier for this issue is: CVE-2010-0745 Can you update security-tracker, thanks. Best regards, Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.9

DSA-2022-1 / CVE-identifiers

2010-07-28 Thread Henri Salo
wikis which restrict access to private files using img_auth.php, or some similar scheme. References: http://seclists.org/oss-sec/2010/q1/189 Best regards, Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkxQRAYACgkQXf6hBi6kbk/6YACbBvKmsa4hsVbIWv29Hll5tRjP

Debian and CVE-2010-0624

2010-03-10 Thread Henri Salo
Is vulnerability CVE-2010-0624 fixed in Debian-packages already? --- Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/2010031014

Re: dt_ssh5

2009-11-04 Thread Henri Salo
ed.html>. Could you email me the file, thanks? --- Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Xpdf Integer overflow

2009-10-16 Thread Henri Salo
Is update for Xpdf-vulnerability coming soon for this issue: <http://securityreason.com/securityalert/6674> --- Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Re: rootkit not found by rkhunter

2009-10-04 Thread Henri Salo
skype: thomaskrichel You should use apticron and apt-dater. --- Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Re: rootkit not found by rkhunter

2009-10-04 Thread Henri Salo
On Sun, 4 Oct 2009 10:15:35 -0400 Thomas Krichel wrote: > I am running debian testing, 2.6.30 kernel. > > I have a rootkit installed on a bunch of machines that rkhunter > does not find. This appears after infection with SHV4 / SHV5, > which rkhunter found. > > Here it works to allow

Re: Are these scan logs dangerous ?

2009-07-05 Thread Henri Salo
ervice > > > > But port 113 auth is open ! So which service has opened port 113 ? netstat -lnop|grep ":113" --- Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Re: Linux infected ?

2009-01-29 Thread Henri Salo
they are in > ~/.wine, but I haven't used Wine in years) and start again. > > -- > Eduardo M KALINOWSKI > edua...@kalinowski.com.br > http://move.to/hpkb > If you do this, please make sure that there isn't any wine-processes running on system. Those might still be effec

Re: Linux infected ?

2009-01-29 Thread Henri Salo
onfigured to open win32 binaries in wine, which in my opinion isn't very smart thing to do, because of these cases. --- Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Amarok CVE-2009-0135 and CVE-2009-0136

2009-01-19 Thread Henri Salo
d=CVE-2009-0135 2: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0136 3: http://lists.debian.org/debian-security-announce/2009/msg00013.html --- Henri Salo -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble?

Re: Rainbow tables on Linux?

2008-10-23 Thread Henri Salo
can be found from http://www.openwall.com/john/. You should also check their wiki. - Henri Salo -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: antivirus for webserver

2008-10-06 Thread Henri Salo
I'll bet you don't need those in your webserver. - Henri Salo -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Microsoft-IIS/6.0 serves up Debian... WTF!

2008-06-08 Thread Henri Salo
and switched this month. > Seems very weird to me. > > > Regards, > That server looks like lighttpd. -- Henri Salo +358407705733 GPG ID: 2EA46E4F fp: 14D0 7803 BFF6 EFA0 9998 8C4B 5DFE A106 2EA4 6E4F signature.asc Description: PGP signature

Re: secure installation

2007-09-05 Thread Henri Salo
On Wed, 05 Sep 2007 10:01:37 +0200 Johannes Wiedersich <[EMAIL PROTECTED]> wrote: > It was installed before etch went stable, though. That shouldn't effect anything or at least development tries to avoid that kind of errors. --- Henri Salo +358407705733 GPG ID: 2EA46E4F fp:

Re: secure installation

2007-08-15 Thread Henri Salo
by default on our > workstations? There shouldn't be any ports open to internal network after installation. Where do you need firewall after installation when you can make one i.e. with iptables? - Henri 'fgeek' Salo -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: spooky windows script

2007-05-08 Thread Henri Salo
k monitor that this is coming from outside; > IP-number and user name vary.) > > After that all is back to normal. > > Now this is of course a nuisance, but is it also a thread? And what > can be done against it? > > Anybody got a clue on this? > > Tia, > >

Re: Hardened linux (debian) recommendation?

2007-03-17 Thread Henri Salo
4kwCgiU7W > W5eNa1r5DSwcVswrWlB2W+8= > =RilM > -END PGP SIGNATURE- > > You can patch your kernel with http://grsecurity.net/ - --- Henri Salo [EMAIL PROTECTED] 0407705733 PGP: http://fgeek.fi/pgp/fgeek-fi-key.asc -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.6 (GN

Re: Firefox on testing hijacked by http://www.megago.com/l/?

2006-09-04 Thread Henri Salo
something about hoaxes or virii you can delete and clean it with help. After all it can be someone from your family and this isn't actual debian security -related problem. -- Henri Salo | [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscrib

Re: When are security updates effective?

2006-08-30 Thread Henri Salo
closes all firefoxes after update. Haha that wouldn't be so disturbing. -- Henri Salo | [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

chrootkit sniffers

2006-08-14 Thread Henri Salo
It is actually saying that in both stable and unstable. I don't have testing versions. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: chkrootkit sniffers

2006-08-14 Thread Henri Salo
Lothar Ketterer wrote: Hi, It remains strange because normally, lo is a non-broadcast interface. Maybe it would help to know how Henri has his network configured. Mine is configured with ifupdown, /etc/network/interfaces looks like this: auto lo eth0 iface lo inet loopback iface

chkrootkit sniffers

2006-08-10 Thread Henri Salo
that serious? -- Henri Salo [EMAIL PROTECTED] 0407705733 -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]