Re: CVE-2006-0225, scponly shell command possible

2006-02-15 Thread Steve Kemp
On Wed, Feb 15, 2006 at 02:01:51PM +1100, Geoff Crompton wrote: This bug has been closed for unstable (see bug 350964) with the 4.6 upload, but will it be fixed for sarge? Please see DSA-969-1 released two days ago: http://www.us.debian.org/security/2006/dsa-969 Sarge is fixed.

Re: Bug#350964: CVE-2006-0225, scponly shell command possible

2006-02-15 Thread Thomas Wana
Steve Kemp wrote: On Wed, Feb 15, 2006 at 02:01:51PM +1100, Geoff Crompton wrote: This bug has been closed for unstable (see bug 350964) with the 4.6 upload, but will it be fixed for sarge? Please see DSA-969-1 released two days ago:

Invalid signature for Releases packages

2006-02-15 Thread Gaƫtan Duchaussois
Hi, I use apt-check-sigs to check the signature of Release packages before making an apt-get install/upgrade. Since January the 1st, apt-check-sigs complains about bad sigs for Source: deb-src ftp://ftp.fr.debian.org/debian/ sarge main contrib non-free on all mirrors. Release packages are signed