Re: Please announce current lack of security support

2005-07-27 Thread Vincent Bernat
OoO En cette fin de matinée radieuse du mardi 26 juillet 2005, vers 11:02, martin f krafft [EMAIL PROTECTED] disait: However, I feel that our users should be told about the problem, and not just through Joey's blog entry. Thus, can I please urge the security team to release an appropriate

Re: a compromised machine

2005-07-27 Thread Davide Prina
Nejc Novak ha scritto: So, for now i killed this process, disabled the cronjob and killed web server - there is now way the attacker is capable of coming back into server or is there a chance that there is another backdoor installed somewhere (chkrootkit doesn't find anything). try also

Re: [SECURITY] [DSA 765-1] New heimdal packages fix arbitrary code execution

2005-07-27 Thread Olaf Meeuwissen
[EMAIL PROTECTED] (Martin Schulze) writes: -- Debian Security Advisory DSA 765-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 22nd, 2005

Re: Please announce current lack of security support

2005-07-27 Thread martin f krafft
also sprach Vincent Bernat [EMAIL PROTECTED] [2005.07.27.0805 +0200]: security-announce seems unavailable too. How so? lists.debian.org is up and a message sent and signed by the security team to -security-announce should show up. Or am I missing something? -- Please do not send copies of list

Security fixes for mozilla and firefox in Sarge?

2005-07-27 Thread Holger Mense
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the latest upload of mozilla in sarge is from friday, 13th of May. The latest upload of firefox in sarge is from monday, 16th of May. Since then several security issues were found in both programms. The issues in firefox were fixed by upload of a

IPsec from native KAME in 2.6 kernel to FreeS/WAN on 2.4

2005-07-27 Thread Igor Goldenberg
Hello. I have the central security gateway (server) with FreeS/WAN v2.06 and a number of client security gateways with the same FreeS/WAN on its. Between the server and client gateways exists more then one tunnel having the same endpoints. For example, for scheme net1/24 == gw1 ... gw2 == (serv1

Re: [SECURITY] [DSA 765-1] New heimdal packages fix arbitrary code execution

2005-07-27 Thread Moritz Muehlenhoff
In gmane.linux.debian.devel.security, you wrote: Package: heimdal Vulnerability : buffer overflow Problem-Type : remote Debian-specific: no CVE ID : CAN-2005-0469 Gaël Delalleau discovered a buffer overflow in the handling of the LINEMODE suboptions in telnet clients.

Re: Please announce current lack of security support

2005-07-27 Thread Vincent Bernat
OoO En cette fin de matinée radieuse du mercredi 27 juillet 2005, vers 11:21, martin f krafft [EMAIL PROTECTED] disait: security-announce seems unavailable too. How so? lists.debian.org is up and a message sent and signed by the security team to -security-announce should show up. Or am I

Re: last -t lists all entries in wtmp

2005-07-27 Thread J.A. de Vries
On 2005-07-25 @ 10:44:42 (week 30) Albert Dorofeev wrote: I do not think it is date and later. It is from the beginning of the wtmp to the date specified. And that's the intended behaviour. Hi Albert, You are correct. This thread was moved to debian-user where all this was resolved some days

Philippe CAILLEAUD/SIEGE/MAIF est absent.

2005-07-27 Thread philippe . cailleaud
Je serai absent(e) du 27/07/2005 au 19/08/2005. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 765-1] New heimdal packages fix arbitrary code execution

2005-07-27 Thread Olaf Meeuwissen
Moritz Muehlenhoff [EMAIL PROTECTED] writes: In gmane.linux.debian.devel.security, you wrote: Package: heimdal Vulnerability : buffer overflow Problem-Type : remote Debian-specific: no CVE ID : CAN-2005-0469 Gaël Delalleau discovered a buffer overflow in the handling of

Re: Security fixes for mozilla and firefox in Sarge?

2005-07-27 Thread Sam Morris
Florian Weimer wrote: I'm not sure if there will be uploads of new Firefox (or Mozilla) version to the volatile distribution. A first step is building a new Firefox package on sarge, and I'm not aware of anyone doing this. I'm attaching a diff against mozilla-firefox_1.0.6-1.diff that makes