Re: [SECURITY] [DSA-594-1] New Apache packages fix arbitrary code execution

2004-11-17 Thread Steve Suehring
If I'm not mistaken the vulnerabilities existed in two files found in apache-common. Since apache-common is a prerequisite for apache-ssl, updating apache-common should correct the vulnerability. I could be wrong and I'm sure someone will correct me if I am. :) Steve On Wed, Nov 17, 2004, Ada

Re: [SECURITY] [DSA 594-1] New Apache packages fix arbitrary code execution

2004-11-17 Thread Adam Morley
On Wed, Nov 17, 2004 at 01:05:54PM +0100, Martin Schulze wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > - -- > Debian Security Advisory DSA 594-1 [EMAIL PROTECTED] > http://www.debian.org/secu

Re: [SECURITY] [DSA 594-1] New Apache packages fix arbitrary code execution

2004-11-17 Thread Lupe Christoph
Quoting [EMAIL PROTECTED]: > Nur zu Info - und um anzumerken dass uns das nicht betrifft. Ich moechte noch anmerken, dass uns die Mail auch nicht betrifft :-P Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | "... putting a mail server on the Internet wit

Re: [SECURITY] [DSA 594-1] New Apache packages fix arbitrary code execution

2004-11-17 Thread rm
Nur zu Info - und um anzumerken dass uns das nicht betrifft. Gruss RalfD On Wed, Nov 17, 2004 at 01:05:54PM +0100, Martin Schulze wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > - -- > Debian Security Advisory

Re: any DSA for CAN-2004-0930

2004-11-17 Thread Rolf Kutz
* Quoting Hideki Yamane ([EMAIL PROTECTED]): > >It has been fixed for unstable at least. > > How about CAN-2004-0600 and CAN-2004-0686 for samba in stable? There is no Samba3 in stable. - Rolf -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [E

Re: any DSA for CAN-2004-0930

2004-11-17 Thread Hideki Yamane
Hi, "Wed, 17 Nov 2004 00:11:34 -0500", "Stephen Gran" "Re: any DSA for CAN-2004-0930" >samba (3.0.8-1) unstable; urgency=high > > * New upstream package. Urgency set to "high" because of a potential >Denial of Service vulnerability in previous 3.0.x releases >(CAN-2004-0930). (Eloy) >