Iceweasel and web browsers vulnerabilty concerning poodle.

2014-10-16 Thread Marco Galicia
Hi, As I know, a new vulnerability called poodle has been discovered regadirng https. This vulnerabilty takes advantage of the ssl 3.0, and forcecs the https protocol to use this outdated protocol. I have been told that a fix for this vulnerabilty is to disable the use of this protocol in the

Re: Efficient way to keep track of security updates

2015-01-29 Thread Marco Galicia
Hi, i have been reading a little more on the libc vulnerability now called ghost. I have a question: Does using something like the Grsecurity kernel helps prevent these type of vulnerabilities? In Ghost case, a Grsecurity kernel would help? Stephen: doesn't apticron does the same job as your

Re: Efficient way to keep track of security updates

2015-01-29 Thread Marco Galicia
, 2015-01-30 at 00:22 -0600, Marco Galicia wrote: Does using something like the Grsecurity kernel helps prevent these type of vulnerabilities? grsec can mitigate weaknesses in other software but it does not prevent those vulnerabilities from existing, it can just change the effects of being

Some perl packages not available in mirrors.

2015-06-30 Thread Marco Galicia
While trying to build some lxc from debian I noticed that some perl related packages failed to download. I tried changing mirrors and then verifying manually and i can say that some perl packages are missing in all the debian mirrors. This can make a lot of installations of Debian to fail due to