Bug#435521: closed by Mark Purcell [EMAIL PROTECTED] (Re: Asterisk SIP DOS Vulnerability)

2007-08-18 Thread Martin Schulze
Faidon Liambotis wrote: Granted, we have a very very bad record as maintainers of supporting this security-wise but I think we can try to change that. I certainly will try my best to provide you with patched versions to upload. I haven't discuss this with the rest of the team yet but I think

Bug#435521: closed by Mark Purcell [EMAIL PROTECTED] (Re: Asterisk SIP DOS Vulnerability)

2007-08-18 Thread Kilian Krause
Hi Moritz, On Fri, Aug 17, 2007 at 10:53:48PM +0200, Moritz Muehlenhoff wrote: Mark Purcell wrote: On Wed, 8 Aug 2007, Lionel Elie Mamane wrote: Yes, but we should still fix that in stable, not only unstable. Yes I wasn't suggesting that we don't fix it in stable, but rather that a

Bug#435521: closed by Mark Purcell [EMAIL PROTECTED] (Re: Asterisk SIP DOS Vulnerability)

2007-08-18 Thread Mark Purcell
On Sat, 18 Aug 2007, Kilian Krause wrote: Comments? If the rest of pkg-voip developers agrees, i'll just put up a pseudo RC-bug against asterisk to make sure it's not progressing into testing anymore (and therefore not contained in stable release of Lenny and newer). Kilian, I don't

Bug#435521: closed by Mark Purcell [EMAIL PROTECTED] (Re: Asterisk SIP DOS Vulnerability)

2007-08-18 Thread Faidon Liambotis
Martin Schulze wrote: Faidon Liambotis wrote: Granted, we have a very very bad record as maintainers of supporting this security-wise but I think we can try to change that. I certainly will try my best to provide you with patched versions to upload. I haven't discuss this with the rest of the

Bug#435521: closed by Mark Purcell [EMAIL PROTECTED] (Re: Asterisk SIP DOS Vulnerability)

2007-08-17 Thread Moritz Muehlenhoff
Mark Purcell wrote: On Wed, 8 Aug 2007, Lionel Elie Mamane wrote: Yes, but we should still fix that in stable, not only unstable. Yes I wasn't suggesting that we don't fix it in stable, but rather that a fix was available and had been uploaded to Debian (unstable). The BTS supports

Bug#435521: closed by Mark Purcell [EMAIL PROTECTED] (Re: Asterisk SIP DOS Vulnerability)

2007-08-17 Thread Faidon Liambotis
[removing pkg-voip and security team members from the Cc list since they will get the mail] Moritz Muehlenhoff wrote: For Etch we need to bite the bullet and continue to support it (see my previous mail to Faidon), but with the current strain of vulnerabilities (19 in 2007 alone!) we can't

Bug#435521: closed by Mark Purcell [EMAIL PROTECTED] (Re: Asterisk SIP DOS Vulnerability)

2007-08-08 Thread Mark Purcell
On Wed, 8 Aug 2007, Lionel Elie Mamane wrote: Yes, but we should still fix that in stable, not only unstable. Yes I wasn't suggesting that we don't fix it in stable, but rather that a fix was available and had been uploaded to Debian (unstable). The BTS supports version tracking and even though