Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread s. keeling
Incoming from Rick Moen: > Quoting s. keeling ([EMAIL PROTECTED]): > > > Well, even mutt will, if you turn on autoload crap in .muttrc and load > > up your .mailcap with stupid helper apps. > > > > Out of the box, no, mutt doesn't do that. > > Ja. We might call the .mailcap scenario the "aim-gu

Re: .desktop arbitrary program execution (was: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution)

2005-01-18 Thread Alvin Oga
On Tue, 18 Jan 2005, David Mandelberg wrote: > Save to your GNOME/KDE desktop (like many newbies do) and double click the > new > icon. .desktop files (currently) don't need the x bit set to work, so no > chmod'ing is necessary. that'd be dumb of the user > This one is pretty harmless (it ju

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread s. keeling
Incoming from Denis O'Toole: > Can you please OT: this Hint: the "d" key will probably do this for you. Please stop interfering with discussions of insecure applications on debian-security. TVM. :-) -- Any technology distinguishable from magic is insufficiently advanced. (*)http://www.s

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread Rick Moen
Quoting s. keeling ([EMAIL PROTECTED]): > Well, even mutt will, if you turn on autoload crap in .muttrc and load > up your .mailcap with stupid helper apps. > > Out of the box, no, mutt doesn't do that. Ja. We might call the .mailcap scenario the "aim-gun-at-my-foot-please" mutt extension. Ma

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread s. keeling
Incoming from Rick Moen: > Quoting David Mandelberg ([EMAIL PROTECTED]): > > > Do you mean to say that opening "message.txt\t\t\t.desktop" which > > happens to be a freedesktop.org compliant launcher for the program "rm > > -rf $HOME" is safe because it's designed for people running one of the > >

Re: .desktop arbitrary program execution (was: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution)

2005-01-18 Thread Rick Moen
Quoting David Mandelberg ([EMAIL PROTECTED]): > Attached. > > Save to your GNOME/KDE desktop (like many newbies do) and double click > the new icon. .desktop files (currently) don't need the x bit set to > work, so no chmod'ing is necessary. I'm sorry, but the question was: Please advise this

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread s. keeling
Incoming from David Mandelberg: > s. keeling wrote: > > Incoming from Moe: > > > >>Martin Schulze wrote: > >> > >>> Part 1 Type: C > >>>Encoding: 8bit > >> > >>After all these months/years of warnings to NEVER open email > >>attachments, why are you sending attachments instead

Re: .desktop arbitrary program execution (was: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution)

2005-01-18 Thread David Mandelberg
Rick Moen wrote: > Quoting David Mandelberg ([EMAIL PROTECTED]): >>Do you mean to say that opening "message.txt\t\t\t.desktop" which >>happens to be a freedesktop.org compliant launcher for the program "rm >>-rf $HOME" is safe because it's designed for people running one of the >>F/OSS products GN

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread Denis O'Toole
Can you please OT: this Regards Denis O'Toole Moe wrote: After all these months/years of warnings to NEVER open email attachments, why are you sendinf attachments instead of in-line? Martin Schulze wrote: Part 1 Type: C Encoding: 8bit -- To UNSUBSCRIBE, email to [E

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread Rick Moen
Quoting David Mandelberg ([EMAIL PROTECTED]): > Do you mean to say that opening "message.txt\t\t\t.desktop" which > happens to be a freedesktop.org compliant launcher for the program "rm > -rf $HOME" is safe because it's designed for people running one of the > F/OSS products GNOME or KDE on a F/O

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread David Mandelberg
s. keeling wrote: > Incoming from Moe: > >>Martin Schulze wrote: >> >>> Part 1 Type: C >>>Encoding: 8bit >> >>After all these months/years of warnings to NEVER open email >>attachments, why are you sending attachments instead of in-line? > > > People who don't use stupid Win

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread s. keeling
Incoming from Moe: > Martin Schulze wrote: > > > >Part 1 Type: C > > Encoding: 8bit > > After all these months/years of warnings to NEVER open email > attachments, why are you sending attachments instead of in-line? People who don't use stupid Windows email clients have no

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread Moe
After all these months/years of warnings to NEVER open email attachments, why are you sendinf attachments instead of in-line? Martin Schulze wrote: > >Part 1 Type: C > Encoding: 8bit -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble?

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread Willy Sjonfjell
test tir, 18,.01.2005 kl. 10.41 +0100, skrev Martin Schulze: plain text document-vedlegg -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 644-1 [EMAIL PROTECT

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread Sebastian Lövdahl
Martin Schulze wrote: This message was modified by F-Secure Anti-Virus E-Mail Scanning. This is what F-Secure gave me. Martin do you send viruses? ;) Sebastian -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 643-1] New queue packages fix buffer overflows

2005-01-18 Thread Daniel van Eeden
Same problem with evolution 2.0.3 On Tue, 2005-01-18 at 05:25 -0500, David wrote: > Hello Martin, > > Just wanted to let you know that the last two announcements you sent > appear as blank messages in Thunderbrid with an unnamed attachment - > perhaps due to the initial blank Content-Type: header

[meta] Set reply-to to something else?

2005-01-18 Thread Adrian von Bidder
Hi, With web-board passwords and two or three auto-acks being posted to this list every week: could we think about setting the Reply-To of debian-security-announce to something else? Perhaps something in ALL CAPS that is not an email address, like Reply-To: EDIT HERE - REPLY TO cheers -- vb

Re: [SECURITY] [DSA 643-1] New queue packages fix buffer overflows

2005-01-18 Thread David
Hello Martin, Just wanted to let you know that the last two announcements you sent appear as blank messages in Thunderbrid with an unnamed attachment - perhaps due to the initial blank Content-Type: header. David On Tue, 18 Jan 2005, Martin Schulze wrote: > -BEGIN PGP SIGNED MESSAGE- >