Re: [SECURITY] [DSA 532-1] New libapache-mod-ssl packages fix multiple vulnerabilities

2004-07-29 Thread Tim Dijkstra
Matt Zimmerman: > The machine which builds security updates for alpha is currently > offline. I'm a bit amazed you depend on only one machine to build those packages... Well for people that have an alpha and didn't compile it yet for their selves, I put a deb at: http://www.famdijkstra.org/~tdyk

Re: [SECURITY] [DSA 532-1] New libapache-mod-ssl packages fix multiple vulnerabilities

2004-07-29 Thread Matt Zimmerman
On Thu, Jul 29, 2004 at 11:56:41AM +0200, Tim Dijkstra wrote: > As the advisory recommended, I 'apt-get upgrade'd my stable boxen, but I > noticed that on my alpha server the only thing that was updated where the > docs. Indeed the advisory doesn't talk about a new version for alpha. Is > there a

Re: PaX on Debian (Kernel Settings)

2004-07-29 Thread Christoph Hellwig
Sorry, no interest in such a mega-patch. If you are interested in getting non-executable stack/heap/etc patches into the debian kernel work with the arch maintainers, for example Dave Miller has added patches based on PaX to sparc lately. For the magic ELF flags please use the non-exec stack anno

Re: [SECURITY] [DSA 532-1] New libapache-mod-ssl packages fix multiple vulnerabilities

2004-07-29 Thread Tim Dijkstra
On Thu, 22 Jul 2004 20:29:33 -0700 Matt Zimmerman <[EMAIL PROTECTED]> wrote: > - > Debian Security Advisory DSA 532-1 > [EMAIL PROTECTED] http://www.debian.org/security/ > Matt Zimmer

Re: FWD: Squirrelmail XSS + SQL security bug?

2004-07-29 Thread Roman Medina-Heigl Hernandez
Hi all. Sorry for my late response. I'm on vacation. Comments inline. On Thu, 22 Jul 2004 20:28:23 +0200 (CEST), you wrote: >About security fixes in the SquirrelMail code; SquirrelMail does not (contrary to >Roman's standpoint) adhere to a obscurity-policy but in stead openly discloses any >se