RE: [SECURITY] [DSA 3031-1] apt security update

2014-09-24 Thread Andrea Whitney
Hi Daniel I get these message - see below, is this something I need to pass on or can I be removed from the list, means nothing to me I'm afraid. Andrea -Original Message- From: Salvatore Bonaccorso [mailto:car...@debian.org] Sent: 23 September 2014 17:18 To:

Re: [SECURITY] [DSA 3031-1] apt security update

2014-09-24 Thread Paul Wise
On Wed, Sep 24, 2014 at 4:25 PM, Andrea Whitney wrote: I get these message - see below, is this something I need to pass on or can I be removed from the list, means nothing to me I'm afraid. I recommend you unsubscribe and have your sysadmin subscribe instead. Each of you need to enter your

Upcoming stable point release (7.7)

2014-09-24 Thread Adam D. Barratt
Hi, The next point release for wheezy (7.7) is scheduled for Saturday, October 18th. Stable NEW will be frozen during the preceding weekend. Regards, Adam -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

bash 4.2 for squeeze

2014-09-24 Thread Darko Gavrilovic
Hi, is there a bash upgrade for squeeze to address below cve? https://www.debian.org/security/2014/dsa-3032 -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive:

Re: bash 4.2 for squeeze

2014-09-24 Thread Thijs Kinkhorst
Hi, On Wed, September 24, 2014 21:43, Darko Gavrilovic wrote: Hi, is there a bash upgrade for squeeze to address below cve? https://www.debian.org/security/2014/dsa-3032 Updates to squeeze-lts are announced on the debian-lts-announce list. There you will find that this bug has indeed been

Re: bash 4.2 for squeeze

2014-09-24 Thread Sven Hoexter
On Wed, Sep 24, 2014 at 03:43:42PM -0400, Darko Gavrilovic wrote: Hi, is there a bash upgrade for squeeze to address below cve? https://www.debian.org/security/2014/dsa-3032 There is already a squeeze lts security announcement but my mirrors do not yet have the update. So it should be

Re: bash 4.2 for squeeze

2014-09-24 Thread kloschi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 09/24/2014 09:43 PM, Darko Gavrilovic wrote: Hi, is there a bash upgrade for squeeze to address below cve? https://www.debian.org/security/2014/dsa-3032 Squeeze is not supported anymore, tho there are still updates available for squeeze-lts

Re: [SECURITY] [DSA 3033-1] nss security update

2014-09-24 Thread DUANE and CHERYL CAREY
Yes, this is the perfect thing for our website Love you Me Sent from my iPhone On Sep 24, 2014, at 8:30 PM, Yves-Alexis Perez cor...@debian.org wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian

Re: [Reproducible-builds] concrete steps for improving apt downloading security and privacy

2014-09-24 Thread Hans-Christoph Steiner
Daniel Kahn Gillmor wrote: Thanks for the discussion, Hans. On 09/19/2014 02:47 PM, Hans-Christoph Steiner wrote: Packages should not be accepted into any official repo, sid included, without some verification builds. A .deb should remain unchanged once it is accepted into any official

Re: [Reproducible-builds] concrete steps for improving apt downloading security and privacy

2014-09-24 Thread W. Martin Borgert
On 2014-09-24 23:05, Hans-Christoph Steiner wrote: * the signature files sign the package contents, not the hash of whole .deb file (i.e. control.tar.gz and data.tar.gz). So preinst and friends would not be signed? Sounds dangerous to me. -- To UNSUBSCRIBE, email to

Re: [Reproducible-builds] concrete steps for improving apt downloading security and privacy

2014-09-24 Thread Hans-Christoph Steiner
W. Martin Borgert wrote: On 2014-09-24 23:05, Hans-Christoph Steiner wrote: * the signature files sign the package contents, not the hash of whole .deb file (i.e. control.tar.gz and data.tar.gz). So preinst and friends would not be signed? Sounds dangerous to me. All package contents

External check

2014-09-24 Thread Raphael Geissert
CVE-2014-0170: RESERVED -- The output might be a bit terse, but the above ids are known elsewhere, check the references in the tracker. The second part indicates the status of that id in the tracker at the moment the script was run. -- To UNSUBSCRIBE, email to

Re: Guidance on no-dsa and adding entries to dsa/dla-needed.txt

2014-09-24 Thread Holger Levsen
Hi, On Dienstag, 23. September 2014, Michael Gilbert wrote: There is a page that lists candidates for DTSA (Debian Testing Security Announcements), which aren't actually done anymore I can remove it, if it's really not used at all anymore. , but something like that would be very useful for

Re: Guidance on no-dsa and adding entries to dsa/dla-needed.txt

2014-09-24 Thread Salvatore Bonaccorso
Hi all, On Wed, Sep 24, 2014 at 02:37:00PM +0200, Holger Levsen wrote: [...] Then the separate text files could go away, and we can just use no-dsa in the CVE list to keep those pages up to date. you mean those dsa-needed.txt and dla-needed.txt files? We could. But right now we also use

Processed: user www.debian....@packages.debian.org, forcibly merging 762254 751403, usertagging 751403

2014-09-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: user www.debian@packages.debian.org Setting user to www.debian@packages.debian.org (was taf...@debian.org). forcemerge 762254 751403 Bug #762254 [www.debian.org] explain LTS on the www.d.o website Bug #751403 [www.debian.org]