Re: [gna-private] [SECURITY] [DSA 987-1] New tar packages fix arbitrary code execution

2006-03-08 Thread Florian Weimer
* Steve Kemp: > On Wed, Mar 08, 2006 at 09:41:39AM +0100, Mathieu Roy wrote: > >> > Package: tar >> > Vulnerability : buffer overflow >> > Problem-Type : local(remote) >> >> What does mean >> local(remote) >> >> Does it means local... or remote? > > Local. But remote in the s

Re: first A record of security.debian.org extremely slow

2006-03-08 Thread Florian Weimer
* Michelle Konzack: > 1) Download Packages.gz/Sources.gz and check for changes I think you should look at the Release file first, at least if you don't use If-Modified-Since or similar conditional requests. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Tro

Re: first A record of security.debian.org extremely slow

2006-03-08 Thread martin f krafft
also sprach Michelle Konzack <[EMAIL PROTECTED]> [2006.02.28.1824 +0100]: > I can not use rsync because I have a different directory structure AND > I do not want to kill one of the security mirrors of debian, fow often > should I poll the Packages.gz/Sources.gz for changes daily? Once. -- Pleas

Re: [gna-private] [SECURITY] [DSA 987-1] New tar packages fix arbitrary code execution

2006-03-08 Thread Moritz Muehlenhoff
Mathieu Roy wrote: >> > What does mean >> >local(remote) >> > >> > Does it means local... or remote? >> >> Local. But remote in the sense that you may receive a .tar file >> from a remote source. > > Ok, thanks for the input. > > Looks like oxymoron, a bit confusing though (but I have no p

Re: [gna-private] [SECURITY] [DSA 987-1] New tar packages fix arbitrary code execution

2006-03-08 Thread Mathieu Roy
Le Mercredi 8 Mars 2006 10:17, Steve Kemp a écrit : > On Wed, Mar 08, 2006 at 09:41:39AM +0100, Mathieu Roy wrote: > > > Package: tar > > > Vulnerability : buffer overflow > > > Problem-Type : local(remote) > > > > What does mean > > local(remote) > > > > Does it means local... or re

Re: [gna-private] [SECURITY] [DSA 987-1] New tar packages fix arbitrary code execution

2006-03-08 Thread Steve Kemp
On Wed, Mar 08, 2006 at 09:41:39AM +0100, Mathieu Roy wrote: > > Package: tar > > Vulnerability : buffer overflow > > Problem-Type : local(remote) > > What does mean > local(remote) > > Does it means local... or remote? Local. But remote in the sense that you may receive a

Re: [gna-private] [SECURITY] [DSA 987-1] New tar packages fix arbitrary code execution

2006-03-08 Thread Mathieu Roy
Le Mardi 7 Mars 2006 15:19, Moritz Muehlenhoff a écrit : > -- > Debian Security Advisory DSA 987-1 [EMAIL PROTECTED] > http://www.debian.org/security/ Moritz Muehlenhoff > March 7th,