Re: [Fwd: security]

2005-01-29 Thread Jan Lhr
Greetings,... Am Samstag, 29. Januar 2005 16:05 schrieb michael: On debian-user it was suggested I also post this here, thanks, Michael Forwarded Message From: michael [EMAIL PROTECTED] To: debian user debian-user@lists.debian.org Subject: security Date: Fri, 28 Jan 2005

CAN-2003-0020?

2004-04-17 Thread Jan Lhr
Greetings, what about http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020 ? Is debian finally going to fix it? keep smiling yanosz -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 479-1] New Linux 2.4.18 packages fix local root exploit (source+alpha+i386+powerpc)

2004-04-14 Thread Jan Lhr
Greetings, Am Mittwoch, 14. April 2004 16:52 schrieb Martin Schulze: -- Debian Security Advisory DSA 479-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze

Re: Known vulnerabilities left open in Debian?

2004-03-22 Thread Jan Lhr
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Greetings, Am Montag, 22. März 2004 21:16 schrieb Bryan Allen: On Mar 22, 2004, at 2:57 PM, Jan Lühr wrote: Cron is another example - the be honest, the debian security team seems to be crippled by the debian release policy. Because of this

mozilla - the forgotten package?

2004-03-09 Thread Jan Lhr
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Greetings, over the last months, various security related bugs in mozilla appeared and were fixed in new versions of mozilla - but what about the debian package? Are there any efforts for making mozilla secure or to backport the mozilla patches to

Tripwire (clone) which would you prefer?

2004-02-23 Thread Jan Lhr
Greetings, well, I looking for an open source intrusion detection. At first, tripwire caputures my attention, but the last open source version seems to be three years old - is it still in development or badly vulnerable? Then I searched for tripwire in the woody packages and found integrit and

Re: DSA 438 - bad server time, bad kernel version or information delayed?

2004-02-22 Thread Jan Lhr
Greetings, Am Sonntag, 22. Februar 2004 10:09 schrieb Jim Richardson: On Sat, 21 Feb 2004 22:20:05 +0100, Matt Zimmerman [EMAIL PROTECTED] wrote: On Sat, Feb 21, 2004 at 11:09:09AM +0100, Jan L?hr wrote: Am Samstag, 21. Februar 2004 01:10 schrieb Matt Zimmerman: .. CERT rarely has

output of last

2004-02-21 Thread Jan Lhr
Greetings, I discovered some strange output of the last command on our Woody Terminalserver (for X11). I have already posted it on debian-user-german, but I didn't get any answer. (I hope you don't mind, if I post it for the english speaking majority) Although I hope it is not security

Re: DSA 438 - bad server time, bad kernel version or information delayed?

2004-02-19 Thread Jan Lhr
Greetings, Am Donnerstag, 19. Februar 2004 09:39 schrieb Jean Christophe ANDR: Le jeudi 19 fvrier 2004 09h24 (+0100), Jan Lhr crivait : What about establishing some kind of warning service? E.g. sshd has a well known serious leak, you should shut it down for the next few days. Warning

Re: DSA 438 - bad server time, bad kernel version or information delayed?

2004-02-19 Thread Jan Lhr
Greeting,. Am Donnerstag, 19. Februar 2004 15:12 schrieb Florian Weimer: Jan Lühr wrote: You don't. Tough luck, of course, but that's the price for running affordable, off-the-shelf software (free or proprietary). well, this might be a reason for using computers in situations we use