[Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2011-03-23 Thread Julien Valroff
** Changed in: rkhunter (Ubuntu) Status: Confirmed = Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/493607 Title: rkhunter reports openssl and sshd versions out of date --

[Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2010-02-01 Thread Achim Bohnet
Please note: One has to have a blank at the start and the end of the APP_WHITELIST in rkhunter.conf. Like APP_WHITELIST= openssl:0.9.8g sshd:4.7p1 otherwise first and last entry will never match, as the test used is if [ -n `echo \${APP_WHITELIST}\ | grep \ ${APPLICATION}:${RKHTMPVAR} \` ];

[Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-30 Thread Bug Watch Updater
** Changed in: rkhunter (Debian) Status: Unknown = Fix Released -- rkhunter reports openssl and sshd versions out of date https://bugs.launchpad.net/bugs/493607 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs

[Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-17 Thread Andrew Cholakian
furicle, It looks to me that every security release would require an update to the white list unless I'm mistaken. I just don't see this happening. Flat out skipping the apps check will likely be more practical for rkhunter's maintainer. It's been about a week since this was reported, and the

Re: [Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-17 Thread furicle
On Thu, Dec 17, 2009 at 12:23 PM, Andrew Cholakian andre...@gmail.com wrote: furicle, It looks to me that every security release would require an update to the white list unless I'm mistaken. I don't so. The problem is because they (Debian based distros like Ubuntu) PATCH the current version

[Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-17 Thread Andrew Cholakian
furicle, while it is true that Ubuntu backports fixes from upstream versions its incorrect to say that the version number doesn't change. For instance, on Hardy at the moment the current version of PHP is PHP 5.2.4-2ubuntu5.9 , Ubuntu doesn't increment the 5.2.4-2 part, but it does increment the

Re: [Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-17 Thread furicle
On Thu, Dec 17, 2009 at 7:52 PM, Andrew Cholakian andre...@gmail.com wrote: furicle, while it is true that Ubuntu backports fixes from upstream versions its incorrect to say that the version number doesn't change. For instance, on Hardy at the moment the current version of PHP is PHP

[Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-16 Thread Andrew Cholakian
An easier way to bypass this than white listing (at least for cron jobs) is to simply have it skip the application check. Just set the environment variable $RK_OPT to '--skip-version-check'. The rkhunter cron job automatically adds the contents of $RK_OPT to the rkhunter command line. --

[Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-16 Thread Andrew Cholakian
My apologies, it appears that the --skip-application-check flag doesn't work after all. -- rkhunter reports openssl and sshd versions out of date https://bugs.launchpad.net/bugs/493607 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. --

[Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-16 Thread Andrew Cholakian
It does appear that adding 'apps' to the DISABLE_TESTS option in /etc/rkhunter.conf does work. -- rkhunter reports openssl and sshd versions out of date https://bugs.launchpad.net/bugs/493607 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

Re: [Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-16 Thread furicle
On Wed, Dec 16, 2009 at 12:45 PM, Andrew Cholakian andre...@gmail.com wrote: It does appear that adding 'apps' to the DISABLE_TESTS option in /etc/rkhunter.conf does work. Sure, but wouldn't it be better to only whitelist certain versions rather than skipping them altogether? Keep the

[Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-15 Thread Lars Ljung
** Bug watch added: Debian Bug tracker #560157 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560157 ** Also affects: rkhunter (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560157 Importance: Unknown Status: Unknown ** Changed in: rkhunter (Ubuntu)

[Bug 493607] Re: rkhunter reports openssl and sshd versions out of date

2009-12-10 Thread Alan Porter
About the colons, look in /var/log/rkhunter, and it'll tell you exactly what to whitelist. For named, I had to use named:9.4.2. Still, it seems silly that I have to whitelist apps that are in Ubuntu because of a root-kit checker that is in Ubuntu. I would have hoped that the distro would be