Re: [SECURITY] [DSA 1020-1] New flex packages fix insecure code generation

2006-03-27 Thread Moritz Muehlenhoff
Michael Loftis wrote: > Ouchis anyone anywhere beginning to do an audit of other packages to > find out whats affected by this? The list of potentially affected packages has been identified, but we haven't yet checked all packages for genuine exploitability. If anyone wants to help drop me a

Re: bug in tar 1.14-2.1

2006-03-27 Thread Goswin von Brederlow
Martin Zobel-Helas <[EMAIL PROTECTED]> writes: > Hi Andi, > > On Monday, 27 Mar 2006, you wrote: >> * Martin Zobel-Helas ([EMAIL PROTECTED]) [060324 16:00]: >> > Looks like just rebuilding the security version resolves that error, for >> > whatever reason. Julien and me just cross checked that and

Re: [SECURITY] [DSA 1020-1] New flex packages fix insecure code generation

2006-03-27 Thread Michael Loftis
Ouchis anyone anywhere beginning to do an audit of other packages to find out whats affected by this? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: bug in tar 1.14-2.1

2006-03-27 Thread Martin Zobel-Helas
Hi Andi, On Monday, 27 Mar 2006, you wrote: > * Martin Zobel-Helas ([EMAIL PROTECTED]) [060324 16:00]: > > Looks like just rebuilding the security version resolves that error, for > > whatever reason. Julien and me just cross checked that and got the same > > result. > > > > If noone minds we reu

Re: bug in tar 1.14-2.1

2006-03-27 Thread Andreas Barth
* Martin Zobel-Helas ([EMAIL PROTECTED]) [060324 16:00]: > Looks like just rebuilding the security version resolves that error, for > whatever reason. Julien and me just cross checked that and got the same > result. > > If noone minds we reupload tar with a bumped version number to s-p-u. Is a bi