debian.org/security is wrong to say what it does

2021-12-25 Thread maxwillb
December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" wrote: > So you're raising issues that everyone knows but can't do a great deal about > given the difficulties I hate to be a broken record, but you could edit https://www.debian.org/security/ so that it does not say "We handle all

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread maxwillb
December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" wrote:On Sat, Dec 25, 2021 at 03:36:12PM +0100, maxwillb wrote: > So you're raising issues that everyone knows but can't do a great deal about Then what did you mean by "It's not as if people are massively dropping the ball here" ? By the

Re: Répertoire rules.d vide

2021-12-25 Thread Th.A.C
Bonsoir, Il n'y a aucune info "/udev/rules.d" dans tous ces répertoires citées. Je ne m'attendais pas à ça. /etc/udev/rules.d contenait plein de fichiers "...persistent..." dans toutes les précédentes versions Debian et sur Bullseye c'est 100% vide ! Comment les recréer ? A .Valmer.

carte réseau wifi inopérante

2021-12-25 Thread ajh-valmer
Re bonsoir, Que de problème depuis le passage de Buster 32 bits à Bullseye 64 bits... ! (par une complète nouvelle installation à neuf). 1- DCOPserver (messages d'erreur), 2- ICEauthorithy (messages d'erreur), 3- /udev/rules.d/ inexistant, 4- maintenant, la carte Wifi realtek 2500 pourtant

Re: Répertoire rules.d vide

2021-12-25 Thread ajh-valmer
On Thursday 23 December 2021 20:30:45 didier gaumet wrote: > Udev et moi ça fait deux: one ne peut pas dire que je m'y connais mais > je pense que le répertoire /etc/udev/rules.d a à peu près le même genre > de rôle que le répertoire /etc/apt/sources.list.d : personnaliser une > configuration.

Re: Debian 11.1 Firefox ESR 78.15.0esr add-on icons

2021-12-25 Thread David Christensen
On 12/5/21 2:46 AM, Georgi Naplatanov wrote: On 12/5/21 05:47, David Christensen wrote: debian-user: I installed debian-live-11.1.0-amd64-xfce+nonfree.iso on a Dell Latitude E6520 today: 2021-12-04 19:28:18 dpchrist@laalaa ~ $ cat /etc/debian_version ; uname -a ; dpkg-query -W firefox-esr

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread maxwillb
December 25, 2021 5:41:40 PM CET to...@tuxteam.de wrote:On Sat, Dec 25, 2021 at 05:32:58PM +0100, maxwillb wrote: > Different folks have different criteria for different reasons, so > whether I know a better (according to my criteria?) source is totally > irrelevant here. There are no viable

Re: Firefox ESR EOL

2021-12-25 Thread gene heskett
On Saturday, December 25, 2021 6:06:56 AM EST Andrei POPESCU wrote: > On Lu, 20 dec 21, 06:42:47, gene heskett wrote: > > The first arm board builder to give us two pcie slots or two net ports. or > > even 2 parports WILL OWN this market if the MSRP is under $100 with 2 gigs > > of ram. Ideal

Re: Identity Theft

2021-12-25 Thread Andrei POPESCU
On Ma, 21 dec 21, 10:13:07, Jeremy Ardley wrote: > On 21/12/21 10:09 am, Jeremy Ardley wrote:s. > > There is a type of attack called cross-site scripting (XSS). It's mostly > > been eliminated by latest version browsers, but there are always > > zero-day vulnerabilities. > > > > The effect is

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread tomas
On Sat, Dec 25, 2021 at 05:32:58PM +0100, maxwillb wrote: > December 25, 2021 5:11:20 PM CET to...@tuxteam.de wrote:On Sat, Dec 25, 2021 > at 04:56:31PM +0100, maxwillb wrote: > > > some NVD database... > > Do you know a better source that provides CVE impact metrics? That's not the point, and

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread maxwillb
December 25, 2021 5:11:20 PM CET to...@tuxteam.de wrote:On Sat, Dec 25, 2021 at 04:56:31PM +0100, maxwillb wrote: > some NVD database... Do you know a better source that provides CVE impact metrics? https://www.cvedetails.com/cve/CVE-2021-37973/ has this one too, but they list the outdated

Happy Holidays (was: Re: How to see the list of CRIICALLY vulnerable packages in Debian?)

2021-12-25 Thread rhkramer
On Saturday, December 25, 2021 10:26:06 AM Andrew M.A. Cater wrote: > Hope this helps, as ever, Merry Christmas to all reading the list, by the > w= ay +1 (How's that for laziness ;-)

Re: BUG: Debian 11 version of bibletime

2021-12-25 Thread Andrei POPESCU
On Ma, 21 dec 21, 05:31:31, Richard Owlett wrote: > On 12/18/2021 08:55 AM, Andrei POPESCU wrote: > > On Sb, 18 dec 21, 07:00:56, Richard Owlett wrote: > > > > > > > > Please demonstrate this by showing us the actual run of apt-file as well > > > > as the output of > > > > > > > > dpkg -L

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread maxwillb
December 25, 2021 1:27:03 PM CET Dan Ritter wrote:maxwillb wrote: > Debian doesn't ship Google Chrome. Chromium is a subset of Chrome. This vulnerability is in that subset. HTH Merry Christmas! -- Sent with https://mailfence.com Secure and private email

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread tomas
On Sat, Dec 25, 2021 at 04:56:31PM +0100, maxwillb wrote: > > > December 25, 2021 4:04:03 PM CET Andy Smith wrote:On > Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote: > > > > Dear max, I am the ghost of Christmas Open Source and I encourage you to > > ask for a full refund from

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread maxwillb
December 25, 2021 4:04:03 PM CET Andy Smith wrote:On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote: > Dear max, I am the ghost of Christmas Open Source and I encourage you to ask > for a full refund from Debian and all other volunteer projects that you are > unsatisfied with! I

Re: Re: How to see the list of CRIICALLY vulnerable packages in Debian?

2021-12-25 Thread Andrew M.A. Cater
[Sent by mistake to maxwillb only - forwarding to the list] >From amaca...@einval.com Sat Dec 25 15:16:59 2021 Date: Sat, 25 Dec 2021 15:16:59 + From: "Andrew M.A. Cater" To: maxwillb Subject: Re: How to see the list of CRITICALLY vulnerable packages in Debian? Message-ID: References:

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread Andy Smith
On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote: > No dev so much as bothered to click on the 'NVD' link? > > Merry Christmas! Dear max, I am the ghost of Christmas Open Source and I encourage you to ask for a full refund from Debian and all other volunteer projects that you are

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread maxwillb
December 25, 2021 1:51:39 PM CET "Andrew M.A. Cater" wrote:On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote: > It's not as if people are massively dropping the ball here, in spite of your > apprehension. I'm sure Debian is doing its best. It's just that it's not enough:

Re: doas 101 question

2021-12-25 Thread Greg Wooledge
On Fri, Dec 24, 2021 at 08:32:14PM -0800, David Robert Newman wrote: > I asked doas author Ted Unangst about this. His reply: > > > Sorry, only very limited env replacement can be done in setenv. root's > > environment isn't available before the switch. > > Ergo, it is just as you suspected.

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread Andrew M.A. Cater
On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote: > https://security-tracker.debian.org/tracker/status/release/stable > > shows the list of packages currently considered vulnerable, but it does not > show the severity. > > For example, https://nvd.nist.gov/vuln/detail/CVE-2021-37973 has

Re: How to see the list of CRITICALLY vulnerable packages in Debian?

2021-12-25 Thread Dan Ritter
maxwillb wrote: > https://security-tracker.debian.org/tracker/status/release/stable > > shows the list of packages currently considered vulnerable, but it does not > show the severity. Severity is a matter of opinion. The first opinion should be based on whether the package is even installed.

Re: Acquisition VHS to usb : august vgb350 : pas de peripherique video

2021-12-25 Thread Greg
Le Thu, 23 Dec 2021 14:32:26 +0100, didier gaumet a écrit : > Le jeudi 23 décembre 2021 à 13:58 +0100, Greg a écrit : > > [...] > > y'a un moyen (sans reboot) d'unloader un module ? > > > > > > /sbin/modprobe -r -f  em28xx > > modprobe: FATAL: Module em28xx is in use. > > Tu peux

Re: Acquisition VHS to usb : august vgb350 : pas de peripherique video

2021-12-25 Thread Greg
hello, Le Thu, 23 Dec 2021 14:32:26 +0100, didier gaumet a écrit : > Tu peux peut-être essayer rmmod -f > (d'après les pages man, l'option -f de rmmod a l'air plus appropriée à > ton besoin que celle de modprobe) /sbin/rmmod -f em28xx rmmod: ERROR: ../libkmod/libkmod-module.c:799

Re: Acquisition VHS to usb : august vgb350 : pas de peripherique video

2021-12-25 Thread Greg
Le Sun, 19 Dec 2021 10:00:53 +0100, Fabien R a écrit : > On 18/12/2021 17:09, Greg wrote: > > > kernel: em28xx 3-2:1.0: No AC97 audio processor > > kernel: usb 3-2: Decoder not found > > kernel: em28xx 3-2:1.0: failed to create media graph > Tu peux activer les infos de debug (cf modinfo)

Re: Firefox ESR EOL

2021-12-25 Thread Andrei POPESCU
On Lu, 20 dec 21, 06:42:47, gene heskett wrote: > > The first arm board builder to give us two pcie slots or two net ports. or > even 2 parports WILL OWN this market if the MSRP is under $100 with 2 gigs of > ram. Ideal would be one pci-e, and one net port. SSD's can be put on the > pi4's >

Re: Risc-V [OT: Firefox ESR EOL]

2021-12-25 Thread Andrei POPESCU
On Lu, 20 dec 21, 09:53:54, to...@tuxteam.de wrote: > On Sun, Dec 19, 2021 at 01:44:35PM -0500, Polyna-Maude Racicot-Summerside > wrote: > > [...] > > > Would you have some suggestion if I'd like to try out a Risc-V board ? > > Feeding your fave search engine with, e.g. single board computer