Re: [SECURITY] [DSA 3164-1] typo3-src security update

2015-02-21 Thread Pearse McKenna
please unsubscribe me pearse mckenna On 21 February 2015 at 21:33, Moritz Muehlenhoff j...@debian.org wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3164-1

Re: Should we be alarmed at our state of security support?

2015-02-21 Thread Paul Wise
On Fri, 2015-02-20 at 10:26 -0600, John Goerzen wrote: Quite. But that is a freeform text field. I'm just suggesting we move/add it to the database so it is useable by automatic tools like debsecan and visible to people that are using the tracker. Does that sound doable? I would be

Re: Debian Live CD - unsecured ssh open by default

2015-02-21 Thread Ста Деюс
В Sat, 31 Jan 2015 18:09:58 -0600 John Goerzen jgoer...@complete.org пишет: A friend of mine pointed out to me recently that the Debian Live CD has ssh open to the network by default, and the user account -- which has passwordless sudo to root privileges -- has a password that is well-known

Re: Should we be alarmed at our state of security support?

2015-02-21 Thread Michael Gilbert
John Goerzen wrote: You know, Mike, *explicit* in my original email was a question of what help is needed. I was willing to pitch in and help. I may still be. If your goal is to help, then that's really cool. But how else is someone going to learn that when security-tracker says