Apache 1.3.27 is out...

2002-10-03 Thread Paul Baker
Apache 1.3.27 is out to fix 3 security vulnerabilities in 1.3.26 and below. Are fixed pacakges on their way to security.debian.org? Did ASF notify any vendors in advance of their announcement today? http://www.apache.org/dist/httpd/Announcement.html -- Paul Baker They that can give up

Re: [SECURITY] [DSA 149-1] New glibc packages fix security related problems

2002-08-13 Thread Paul Baker
that need to be restarted just to be safe? I'd rather not have to type in the SSL passphrase for apache+mod_ssl if I don't have to. -- Paul Baker They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. -- Benjamin Franklin, 1759

Re: [SECURITY] [DSA-136-1] Multiple OpenSSL problems

2002-08-01 Thread Paul Baker
continue to try and backport the woody packages to my potato machines myself? -- Paul Baker They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. -- Benjamin Franklin, 1759 GPG Key: http://homepage.mac.com/pauljbaker

Re: [SECURITY] [DSA-136-1] Multiple OpenSSL problems

2002-08-01 Thread Paul Baker
On Thursday, August 1, 2002, at 01:33 PM, Ted Deppner wrote: On Thu, Aug 01, 2002 at 12:19:52PM -0500, Paul Baker wrote: Is there an ETA yet on potato packages, or should I continue to try and backport the woody packages to my potato machines myself? Just as an encouragement, the upgrade

Re: [SECURITY] [DSA-136-1] Multiple OpenSSL problems

2002-08-01 Thread Paul Baker
later (perhaps when sarge is released). Also it expects you to be installing software that has 'make install' etc. Which our software doesn't necessarily have either. So as part of turning everything into debian packages, they will also get nice shiny Makefiles. -- Paul Baker They that can

http://www.debian.org/security/2002/dsa-136

2002-07-30 Thread Paul Baker
The web page for the DSA-136 advisory at http://www.debian.org/security/2002/dsa-136 says Debian GNU/Linux 2.2 (potato) above the list of fixed packages for Woody. Somebody might want to fix that. -- Paul Baker They that can give up essential liberty to obtain a little temporary safety

openssh packages not vulnerable

2002-06-26 Thread Paul Baker
and pam. - -- Paul Baker They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. -- Benjamin Franklin, 1759 GPG Key: http://homepage.mac.com/pauljbaker/public.asc -BEGIN PGP SIGNATURE- Version: GnuPG v1.0.6 (Darwin) Comment

Re: openssh packages not vulnerable

2002-06-26 Thread Paul Baker
the security team will make an official announcement. -- Paul Baker They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. -- Benjamin Franklin, 1759 GPG Key: http://homepage.mac.com/pauljbaker/public.asc -- To UNSUBSCRIBE, email

the openssh exploit

2002-06-25 Thread Paul Baker
an ip that is already denied via tcp_wrapper support in ssh, will it still be able to exploit OpenSSH 3.3? I'm not on the list, so cc me please. -- Paul Baker They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. -- Benjamin

Re: the openssh exploit

2002-06-25 Thread Paul Baker
of the trusted ips?? -- Paul Baker They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. -- Benjamin Franklin, 1759 GPG Key: http://homepage.mac.com/pauljbaker/public.asc -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Re: the openssh exploit

2002-06-25 Thread Paul Baker
to mind. Or just use an unused IP He was talking about spoofing ips that I am allowing access for in my firewall. All the ips I'm allowing are for existing machines, so an unused IP would be one that is not allowed through the firewall already. -- Paul Baker They that can give up essential