Debian and recent TCP vulnerability

2009-09-11 Thread Mlor Apac
Hello What's the status of debian (and linux kernel in general) regarding this recent TCP vulnerability? I have been unable to find any precise information. Let's imagine a server that has publicly accessible tcp service enabled (e.g. http).

Re: Debian and recent TCP vulnerability

2009-09-11 Thread Nick Boyce
Mlor Apac wrote: What's the status of debian (and linux kernel in general) regarding this recent TCP vulnerability? I have been unable to find any precise information. I too am wondering about this. The basic Linux stance is presumably that stated in the Redhat advisory you referenced :

Re: Please help test openssl update

2009-09-11 Thread Kurt Roeckx
On Sun, Sep 06, 2009 at 08:45:12PM +0200, Moritz Muehlenhoff wrote: Please test the openssl packages from http://people.debian.org/~kroeckx/openssl and report success/failure briefly to j...@debian.org. This update deprecates MD-2 (CVE-2009-2409) and we'd like to hear about affected

Re: Debian and recent TCP vulnerability

2009-09-11 Thread Mike Mestnik
On Fri, Sep 11, 2009 at 9:11 AM, Nick Boycen...@glimmer.adsl24.co.uk wrote: Mlor Apac wrote: What's the status of debian (and linux kernel in general) regarding this recent TCP vulnerability? I have been unable to find any precise information. I too am wondering about this. The basic