Re: SubRPC vulnerability: is Debian libc6 affected?

2002-08-12 Thread Ben Collins
> > It looks like it is fixed in glibc 2.2.5-8, but again, it never made > > into official announcement. > > On woody, I believe Ben have been already working, but I don't know > its status. Ben? Should I go ahead for woody? Woody and potato are already uploaded to security.d.o. It's in their ha

Re: SubRPC vulnerability: is Debian libc6 affected?

2002-08-12 Thread GOTO Masanori
At Mon, 12 Aug 2002 11:59:46 +0300, Dmitry Borodaenko wrote: > Recently several glibc vulnerabilities have been published, and there is > only some disjoint information about their status for Debian here and > there. Maybe this bunch of issues is worth one combined DSA that will > explain what is f

Fwd: openssl overflow

2002-08-12 Thread suneo135
Forwarded by suneo135 Forwarded Message - Package:openssl Version:0.9.6c-2 Severity:critical Openssl 0.9.6f changes Changes between 0.9.6e and 0.9.6f [8 Aug 2002] *) Fix ASN1 checks. Check for overflow by comparing with LONG_MAX and get fix the header length calculati

Re: Email Virus Scanner

2002-08-12 Thread Phillip Hofmeister
On Mon, 12 Aug 2002 at 08:00:16PM -0500, Daniel J. Rychlik wrote: > santizer. Do you guys have any suggestions or even a preference over > one or the other? Sophos is considered by many in the security industry to be one of the best. BUT, it is commercial (in other words...green). It supports M

Re: Email Virus Scanner

2002-08-12 Thread Arthur H. Johnson II
I like amavis-perl, but have never set it up under exim. -- Arthur H. Johnson II, Debian GNU/Linux Advocate Catechist, St John Catholic Church, Davison MI USA President, Genesee County Linux Users Group IRC: [EMAIL PROTECTED],#debian YIM: arthurjohnson AIM: bytor4232 ICQ: 31770438 On Mon,

Re: Email Virus Scanner

2002-08-12 Thread David Broome
Hello, I perfer the scanning and rejection to be at SMTP sending time so I think exiscan [1] is a better tool. You can also add-in spamassassin checking at the same time and there is a patch to reject or just tag based the spamassassin responce with a patch from [EMAIL PROTECTED] posted to the exi

Re: Email Virus Scanner - listof um

2002-08-12 Thread Alvin Oga
hi ya here's the collection of virus scanners.. http://www.Linux-Sec.net/Mail/antivirus.gwif.html c ya alvin On Mon, 12 Aug 2002, Daniel J. Rychlik wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Gentlemen, > > I am wanting to setup a good virus scanner for exim. I tried o

Re: Email Virus Scanner

2002-08-12 Thread Christian G. Warden
i recently setup mailscanner with mcafee virusscan and have been pretty happy with it. if you describe the nature of the error, i might be able to help you out. xn On Mon, Aug 12, 2002 at 08:00:16PM -0500, Daniel J. Rychlik wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Gentlem

Email Virus Scanner

2002-08-12 Thread Daniel J. Rychlik
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Gentlemen, I am wanting to setup a good virus scanner for exim. I tried out mailscanner, but it bombs with an error. I tried to fix the error, but I got frustrated. I would like to use mailscanner or even the santizer. Do you guys have any sugge

Re: RUS-CERT Advisory 2002-08:02: Flaw in calloc and similar routines

2002-08-12 Thread Anthony DeRobertis
On Sun, 2002-08-11 at 23:23, Andres Salomon wrote: > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=155529&repeatmerged=yes Thank you! signature.asc Description: This is a digitally signed message part

SubRPC vulnerability: is Debian libc6 affected?

2002-08-12 Thread Dmitry Borodaenko
Recently several glibc vulnerabilities have been published, and there is only some disjoint information about their status for Debian here and there. Maybe this bunch of issues is worth one combined DSA that will explain what is fixed? http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0391