Salut, je vois dans plusieurs listes qu'on a un probleme en ce moment du point de vue securit�.
Sont concern�s : -openssh (extrait de la page openssh.com) Au moins une faille de s�curit� majeure existe sur plusieurs versions d�ploy�es de OpenSSH (2.9.9 � 3.3). Pri�re de consulter la recommandation ISS, ou notre propre recommandation OpenSSH � ce sujet o� de simples correctifs sont fournis pour le probl�me de pr�-authentification. Les syst�mes avec le param�tre UsePrivilegeSeparation positionn� � yes ou ChallengeResponseAuthentication � no ne sont pas affect�s. -apache et mod_ssl et encore glibc sur linux mais on a pas encore toutes les infos... extrait de la mailing list de pure-ftpd :
Basically the thing to do these days is : upgrade everything. OpenSSH needs to be upgraded to 3.4 . Apache needs to be upgraded to 1.3.26 . mod_ssl needs to be upgraded to 2.8.10 . But the worst part is the libc resolver bug. In case you missed it, a serious and remotely exploitable vulnerability has been found in various libc. At least NetBSD, OpenBSD and FreeBSD are vulnerable. The result is not a vulnerability in a specific command. Almost any TCP/IP network related program is vulnerable, including pure-ftpd. Patching and recompiling the C library is not enough, as there are also statically linked programs that can contain the buggy code. There have been some discussions saying that if all your queries are going through a Bind 9 cache, you have a good band-aid for the resolver bug. On the other hand, the official FreeBSD advisory says that there's no workaround. So: time to upgrade everything, or maybe rebuild everything from a clean install. As an immediate workaround, try to disable DNS resolution in all your daemons. For pure-ftpd, using the -H switch may keep it safe. I'm sorry, this thread isn't directly related to pure-ftpd, but as 99.9% of people here are concerned, this is not off-topic. It's probably better to read the same thing in 10 different locations than having his box compromised. -- __ /*- Frank DENIS (Jedi/Sector One) <[EMAIL PROTECTED]> -*\ __ \ '/ <a href="http://www.PureFTPd.Org/"> Secure FTP Server </a> \' / \/ <a href="http://www.Jedi.Claranet.Fr/"> Misc. free software </a> \/
Est ce suffisant pour que les equipes debian nous sortent les nouveau packages "s�cures" ?? Comment �a marche ? -- marco -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

