Re: [SECURITY] [DSA 1291-1] New samba packages fix multiple vulnerabilities

2007-05-16 Thread Noah Meyerhans
On Wed, May 16, 2007 at 09:39:56PM +0200, Thomas Korber wrote: > Moritz Muehlenhoff <[EMAIL PROTECTED]> writes: > > >> Nice work on getting this out. Is sarge going to get an update, is it > >> even affected? I've looked into CVE-2007-2444, and > >> http://www.securityfocus.com/bid/23974/ says tha

Re: [SECURITY] [DSA 1291-1] New samba packages fix multiple vulnerabilities

2007-05-16 Thread Thomas Korber
Moritz Muehlenhoff <[EMAIL PROTECTED]> writes: >> Nice work on getting this out. Is sarge going to get an update, is it >> even affected? I've looked into CVE-2007-2444, and >> http://www.securityfocus.com/bid/23974/ says that the version in sarge >> is affected. > Sarge is still missing a few bu

Re: [SECURITY] [DSA 1291-1] New samba packages fix multiple vulnerabilities

2007-05-16 Thread Moritz Muehlenhoff
Geoff Crompton wrote: > Noah Meyerhans wrote: >> >> Debian Security Advisory DSA-1291-1[EMAIL PROTECTED] >> http://www.debian.org/security/ Noah Meyerhans >> May 15, 2007 >>

Re: debian.org DNSs allow unrestricted zone transfers

2007-05-16 Thread Henrique de Moraes Holschuh
On Tue, 15 May 2007, Abel Martín wrote: > I thought zone transfers should only be possible between DNSs which > have records for the same domain, so why are debian.org DNSs (raff, Only if you have a reason to hide who is in your domain. > possibility of suffering DoS attacks (it serves 254 record