Re: Gaim remote overflows (12x)

2004-01-27 Thread Daniel van Eeden
How about the stable version? On Tue, 2004-01-27 at 19:55, Adam D. Barratt wrote: On Tue, 2004-01-27 at 18:40, Daniel van Eeden wrote: Debian versions of gaim patched? http://security.e-matters.de/advisories/012004.html gaim 0.75-2 was uploaded a couple of hours ago. Changes: gaim

Re: Gaim remote overflows (12x)

2004-01-27 Thread Adam D. Barratt
On Tue, 2004-01-27 at 19:07, Daniel van Eeden wrote: [r.e. gaim 0.75-2 being uploaded to sid] How about the stable version? No idea, I'm afraid. Your best bet would be to ask the maintainer (yes, I noticed the CC on the first mail) or wait a day or two and see if a DSA appears. Adam -- To

Re: Gaim remote overflows (12x)

2004-01-27 Thread Jan Minar
On Tue, Jan 27, 2004 at 06:55:15PM +, Adam D. Barratt wrote: On Tue, 2004-01-27 at 18:40, Daniel van Eeden wrote: http://security.e-matters.de/advisories/012004.html gaim 0.75-2 was uploaded a couple of hours ago. Hi, all. Although the advisory says any version = 0.75 is vulnerable,

Re: Gaim remote overflows (12x)

2004-01-27 Thread Pieter-Paul Spiertz
Hi, On Tue, 27 Jan 2004, Daniel van Eeden wrote: How about the stable version? The stable version deserves updating for another interesting reason; since October 15, 2003 MSN requires SSL. Gaim 0.58 (the archaic version in woody) does not support that; SSL was added in 0.64 iirc. Can actually

Fwd: Re: Gaim remote overflows (12x)

2004-01-27 Thread Daniel van Eeden
-Forwarded Message- From: Martin Schulze [EMAIL PROTECTED] To: Daniel van Eeden [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: Re: Gaim remote overflows (12x) Date: Tue, 27 Jan 2004 19:58:22 +0100 Daniel van Eeden wrote: Are the debian versions already patched? http

Re: Gaim remote overflows (12x)

2004-01-27 Thread Jan Minar
On Tue, Jan 27, 2004 at 08:30:53PM +0100, Pieter-Paul Spiertz wrote: Can actually *any* application in stable connect to MSN? psi? -- Jan Minar Please don't CC me, I'm subscribed. x 9 pgp0.pgp Description: PGP signature

Gaim remote overflows (12x)

2004-01-27 Thread Daniel van Eeden
Debian versions of gaim patched? http://security.e-matters.de/advisories/012004.html -- Daniel van Eeden [EMAIL PROTECTED] http://compukid.no-ip.org/ jabber: [EMAIL PROTECTED] aim: Compukid128 icq: 36952189

Re: Gaim remote overflows (12x)

2004-01-27 Thread Adam D. Barratt
On Tue, 2004-01-27 at 18:40, Daniel van Eeden wrote: Debian versions of gaim patched? http://security.e-matters.de/advisories/012004.html gaim 0.75-2 was uploaded a couple of hours ago. Changes: gaim (1:0.75-2) unstable; urgency=medium . * Security update to fix 12 possible buffer

Re: Gaim remote overflows (12x)

2004-01-27 Thread Daniel van Eeden
How about the stable version? On Tue, 2004-01-27 at 19:55, Adam D. Barratt wrote: On Tue, 2004-01-27 at 18:40, Daniel van Eeden wrote: Debian versions of gaim patched? http://security.e-matters.de/advisories/012004.html gaim 0.75-2 was uploaded a couple of hours ago. Changes: gaim

Re: Gaim remote overflows (12x)

2004-01-27 Thread Adam D. Barratt
On Tue, 2004-01-27 at 19:07, Daniel van Eeden wrote: [r.e. gaim 0.75-2 being uploaded to sid] How about the stable version? No idea, I'm afraid. Your best bet would be to ask the maintainer (yes, I noticed the CC on the first mail) or wait a day or two and see if a DSA appears. Adam

Re: Gaim remote overflows (12x)

2004-01-27 Thread Jan Minar
On Tue, Jan 27, 2004 at 06:55:15PM +, Adam D. Barratt wrote: On Tue, 2004-01-27 at 18:40, Daniel van Eeden wrote: http://security.e-matters.de/advisories/012004.html gaim 0.75-2 was uploaded a couple of hours ago. Hi, all. Although the advisory says any version = 0.75 is vulnerable,

Re: Gaim remote overflows (12x)

2004-01-27 Thread Pieter-Paul Spiertz
Hi, On Tue, 27 Jan 2004, Daniel van Eeden wrote: How about the stable version? The stable version deserves updating for another interesting reason; since October 15, 2003 MSN requires SSL. Gaim 0.58 (the archaic version in woody) does not support that; SSL was added in 0.64 iirc. Can actually

Fwd: Re: Gaim remote overflows (12x)

2004-01-27 Thread Daniel van Eeden
-Forwarded Message- From: Martin Schulze [EMAIL PROTECTED] To: Daniel van Eeden [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: Re: Gaim remote overflows (12x) Date: Tue, 27 Jan 2004 19:58:22 +0100 Daniel van Eeden wrote: Are the debian versions already patched? http

Re: Gaim remote overflows (12x)

2004-01-27 Thread Jan Minar
On Tue, Jan 27, 2004 at 08:30:53PM +0100, Pieter-Paul Spiertz wrote: Can actually *any* application in stable connect to MSN? psi? -- Jan Minar Please don't CC me, I'm subscribed. x 9 pgpv9BDuAI4Cp.pgp Description: PGP signature

Re: Gaim remote overflows (12x)

2004-01-27 Thread Robert McQueen
On Tue, 2004-01-27 at 18:40, Daniel van Eeden wrote: Debian versions of gaim patched? http://security.e-matters.de/advisories/012004.html As observed by others on this list, I uploaded 0.75-2 earlier today with RedHat's patch. The security team are apparently dealing with the version in stable,