Security update for Debian Testing - 2011-01-27

2011-01-26 Thread Testing Security Team
This automatic mail gives an overview over security issues that were recently fixed in Debian Testing. The majority of fixed packages migrate to testing from unstable. If this would take too long, fixed packages are uploaded to the testing-security repository instead. It can also happen that

Re: [SECURITY] [DSA 2151-1] New OpenOffice.org packages fix several vulnerabilities

2011-01-26 Thread Kurt Roeckx
On Wed, Jan 26, 2011 at 05:18:12PM +0100, Martin Schulze wrote: For the upcoming stable distribution (squeeze) these problems have been fixed in version 3.2.1-11+squeeze1. For the unstable distribution (sid) these problems have been fixed in version 3.2.1-11+squeeze1. When will those

Re: Proposal for update of http://debian.org/CD/faq/#verify

2011-01-26 Thread Török Edwin
On 01/26/2011 02:04 AM, Naja Melan wrote: *3. Could a malicious attacker that feeds me an altered iso image not also feed me an altered SHA256SUMS file? Yes, they could! Http is very easy to intercept. This is where SHA256SUMS.sign comes in. This file is the pgp signature of the ***SHA256SUMS

Re: [SECURITY] [DSA 2151-1] New OpenOffice.org packages fix several vulnerabilities

2011-01-26 Thread Adam D. Barratt
On Wed, 2011-01-26 at 19:06 +0100, Kurt Roeckx wrote: On Wed, Jan 26, 2011 at 05:18:12PM +0100, Martin Schulze wrote: For the upcoming stable distribution (squeeze) these problems have been fixed in version 3.2.1-11+squeeze1. For the unstable distribution (sid) these problems have

Re: [SECURITY] [DSA 2151-1] New OpenOffice.org packages fix several vulnerabilities

2011-01-26 Thread Kurt Roeckx
On Wed, Jan 26, 2011 at 07:49:48PM +, Adam D. Barratt wrote: On Wed, 2011-01-26 at 19:06 +0100, Kurt Roeckx wrote: On Wed, Jan 26, 2011 at 05:18:12PM +0100, Martin Schulze wrote: For the upcoming stable distribution (squeeze) these problems have been fixed in version

Re: [SECURITY] [DSA 2151-1] New OpenOffice.org packages fix several vulnerabilities

2011-01-26 Thread Rene Engelhard
Hi, On Wed, Jan 26, 2011 at 09:27:05PM +0100, Kurt Roeckx wrote: 1:3.2.1-11+squeeze1 has been on security-master for a few days now, but it's not visible yet. It seems it didn't even end up in t-s but directly propagated to t-p-u.. I at least did get the propagation mails but yes, it doesn't

Re: Proposal for update of http://debian.org/CD/faq/#verify

2011-01-26 Thread Naja Melan
I just noticed that in hashtab sha256 is not enabled by default, so I would further add the following sentence to the windows/mac instructions: SHA256 is not enabled by default in HashTab, so you will have to click *options *and enable it. Török Edwin edwinto...@gmail.com wrote: What if you

Bug#611161: provide report of RESERVED issues that have information

2011-01-26 Thread Raphael Geissert
Package: security-tracker Severity: wishlist Hi, It would be great to have a report like the one generated by bin/reserved-but- public. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to

Bug#611162: link to package's changelog entry of fixed version

2011-01-26 Thread Raphael Geissert
Package: security-tracker Severity: wishlist Say package foo was affected by CVE-123 and was fixed in version 1.2.3-1, it would be nice if the tracker added a link to foo's 1.2.3-1 changelog entry. E.g.

Bug#611163: make generated HTML CSS-friendlier

2011-01-26 Thread Raphael Geissert
Package: security-tracker Severity: wishlist In order to apply some CSS the generated code needs to be friendlier, for example: * include ids in the tags * use divs instead of tables Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to