Bug#776718: security-tracker: DSA-3146-1 vs. tracker

2015-01-31 Thread Francesco Poli (wintermute)
Package: security-tracker Severity: normal Hello, the tracker page [1] for DSA-3146-1 [2] seems to lack the links to the relevant CVEs [3][4]. Please update the tracker data. Thanks for your time. [1] https://security-tracker.debian.org/tracker/DSA-3146-1 [2]

Re: are unattended updates a good idea?

2015-01-31 Thread Ml Ml
Thank you very much! Your comments has been really helpful. Cheers, Mario On Sat, Jan 31, 2015 at 12:53 PM, Michael Zoet michael.z...@zoet.de wrote: Hi, Hello List, i have got about 50 Debian 6+7 Servers. They are doing all kind of things like Webserver, Mailserver, DNS, etc… I am using

are unattended updates a good idea?

2015-01-31 Thread Ml Ml
Hello List, i have got about 50 Debian 6+7 Servers. They are doing all kind of things like Webserver, Mailserver, DNS, etc… I am using apticron to keep track of the updates, but i seem to use more and more time updating the hosts. Recently i came across the unattended-upgrade project

Re: are unattended updates a good idea?

2015-01-31 Thread Stephen Dowdy
​Mario, I use 'unattended-upgrades' on a couple hundred enduser desktop workstations. The idea being that most potential exploits in our environment might be through end-user browser/surfing. I choose not to use it on a few hundred servers, most of which are internal or perform specialized

Re: [SECURITY] [DSA 3148-1] chromium-browser end of life

2015-01-31 Thread Michael Gilbert
On Sat, Jan 31, 2015 at 5:44 PM, Darius Jahandarie wrote: Security support for the chromium web browser is now discontinued for the stable distribution (wheezy). Chromium upstream stopped supporting wheezy's build environment (gcc 4.7, make, etc.), so there is no longer any practical way to

Bug#582196: marked as done (regression fix dsa's should not alter previous fixed version info)

2015-01-31 Thread Debian Bug Tracking System
Your message dated Sat, 31 Jan 2015 18:33:05 -0500 with message-id CANTw=moyvdd3k2ga82hejacqo+mtflm8abhyvkvcjxvklql...@mail.gmail.com and subject line Re: Bug#582196: marked as done (regression fix dsa's should not alter previous fixed version info) has caused the Debian Bug report #582196,

Re: [SECURITY] [DSA 3148-1] chromium-browser end of life

2015-01-31 Thread Michael Gilbert
On Sun, Feb 1, 2015 at 12:15 AM, Chris Frey wrote: Can someone please point me to the upstream announcement for dropping gcc 4.7 support? I can't seem to find it, and I'd like to read up on the details why. The answer is in the previous mail I sent. The short answer is C++11. Best wishes,

Bug#776738: security-tracker: end-of-life issues clutter the list of open issues

2015-01-31 Thread Michael Gilbert
I just noticed [0], which already requests support for translating the end-of-life tags onto the source-package pages, so it may be useful to look at both of these issues at the same time. [0] http://bugs.debian.org/772961 -- To UNSUBSCRIBE, email to

Re: Debian Live CD - unsecured ssh open by default

2015-01-31 Thread Evgeny Kapun
This should be fixed in the latest version. See https://bugs.debian.org/741678. On 01.02.2015 03:09, John Goerzen wrote: Hello, A friend of mine pointed out to me recently that the Debian Live CD has ssh open to the network by default, and the user account -- which has passwordless sudo to

Re: are unattended updates a good idea?

2015-01-31 Thread Daniel
On Sat, Jan 31, 2015 at 02:50:31PM +0100, Ml Ml wrote: Thank you very much! Your comments has been really helpful. Cheers, Mario On Sat, Jan 31, 2015 at 12:53 PM, Michael Zoet michael.z...@zoet.de wrote: Hi, Hello List, i have got about 50 Debian 6+7 Servers. They are doing all

Re: [SECURITY] [DSA 3148-1] chromium-browser end of life

2015-01-31 Thread Darius Jahandarie
On Sat, Jan 31, 2015 at 5:13 PM, Michael Gilbert mgilb...@debian.org wrote: - - Debian Security Advisory DSA-3148-1 secur...@debian.org http://www.debian.org/security/ Michael

Re: [SECURITY] [DSA 3148-1] chromium-browser end of life

2015-01-31 Thread Chris Frey
Hi, Can someone please point me to the upstream announcement for dropping gcc 4.7 support? I can't seem to find it, and I'd like to read up on the details why. Thanks, - Chris On Sat, Jan 31, 2015 at 05:13:26PM -0500, Michael Gilbert wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512

Re: are unattended updates a good idea?

2015-01-31 Thread Michael Zoet
Hi, Hello List, i have got about 50 Debian 6+7 Servers. They are doing all kind of things like Webserver, Mailserver, DNS, etc… I am using apticron to keep track of the updates, but i seem to use more and more time updating the hosts. I use apticron, cron-apt on various servers for several

Re: are unattended updates a good idea?

2015-01-31 Thread Andrew Beverley
On Sat, 2015-01-31 at 09:58 +0100, Ml Ml wrote: Do you think it is a good idea to do security updates automatically? I've always avoided this for the same reasons as you, but thinking back over the last 10 years, I don't think I've ever had an update break something, so maybe it's time to try...

Re: are unattended updates a good idea?

2015-01-31 Thread Mattias Horn
We use cron-apt for over a year now to patch around 120 Debian Servers with security fixes every night. In this time we never had a broken security update. But we mostly use them as Webservers or Appservers who run Java-Apps. So if u use highly specialized Software you need to consider for