On Fri, Oct 21, 2011 at 02:32:11PM +0200, Alexander Turcic wrote: > Package: shorewall > Version: 4.4.11.6-3 > > Squeeze shorewall 4.4.11.6-3 does not ship with upstream's > /usr/share/shorewall/helpers file. > > The consequence is that if the user sets LOAD_HELPERS_ONLY=Yes in > the /etc/shorewall/shorewall.conf configuration, some essential > helper modules won't be loaded (e.g. nf_conntrack_ftp, nf_nat_ftp, > nf_conntrack_sip). This leads to broken and unexpected behavior. > Would any of this brokenness constitute a security problem? I ask because the version that is affected is the version Debian stable. An update will require justification to the release managers as to why it should be included in the next point release. That justification needs to be based on severity of the problem and possibly any security-related impacts that the issue may have.
> Not checked: the shorewall6 package could be missing the file, too. > You are correct that this affects shorewall6 as well. Regards, -Roberto -- Roberto C. Sánchez http://people.connexer.com/~roberto http://www.connexer.com
signature.asc
Description: Digital signature

