Security fix for xine-lib 1.1.2 (needs testing)

2008-01-17 Thread Darren Salt
http://alioth.debian.org/~dsalt-guest/ has a fixed 1.1.2 build. It needs some testing (just to check that I've backported it correctly, really) and the changelog needs to be corrected, in line with the entry for 1.1.8-3+lenny1. (This message is mainly to record in the BTS the presence of that buil

re: [32D-0F221B4E-1950] [SECURITY] [DSA 1466-1] New xorg-server packages fix several vulnerabilities

2008-01-17 Thread Support
Thank you for submitting a ticket to support. Your ticket number is [32D-0F221B4E-1950]. Please keep this ticket number for your records and include it in the subject (including brackets) of all future emails regarding this issue. Thank You, Support Staff

Re: CVE 2008-0001 already fixed?

2008-01-17 Thread dann frazier
On Thu, Jan 17, 2008 at 06:27:34PM +0100, Nico Golde wrote: > Hi Christoph, > * Christoph Anton Mitterer <[EMAIL PROTECTED]> [2008-01-17 17:48]: > > Can anybody tell me if this issue is already fixed in the Debian > > sources? (i.e. linux-source- and linux-image packages)? > > No as you can see on

Re: CVE 2008-0001 already fixed?

2008-01-17 Thread Nico Golde
Hi Christoph, * Christoph Anton Mitterer <[EMAIL PROTECTED]> [2008-01-17 17:48]: > Can anybody tell me if this issue is already fixed in the Debian > sources? (i.e. linux-source- and linux-image packages)? No as you can see on: http://security-tracker.debian.net/tracker/CVE-2008-0001 Kind regards

CVE 2008-0001 already fixed?

2008-01-17 Thread Christoph Anton Mitterer
Hi. Can anybody tell me if this issue is already fixed in the Debian sources? (i.e. linux-source- and linux-image packages)? References: http://www.securityfocus.com/bid/27280 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0001 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.14 http://

Re: [SECURITY] [DSA 1465-1] New apt-listchanges packages fix arbitrary code execution

2008-01-17 Thread Steve Kemp
On Thu Jan 17, 2008 at 16:35:47 +0100, Philipp Kern wrote: > Still that breaks because os is not imported. Please fix. Quickly. Done. Steve -- # The Debian Security Audit Project. http://www.debian.org/security/audit -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsub

Re: How about carrying this list on gmane?

2008-01-17 Thread Bjørn Mork
Johannes Graumann <[EMAIL PROTECTED]> writes: > How am I supposed to guess that 'devel' refers to the general? http://gmane.org/find.php?list=debian-security%40lists.debian.org Bjørn -- Save the cruise missiles -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". T

Re: [SECURITY] [DSA 1465-1] New apt-listchanges packages fix arbitrary code execution

2008-01-17 Thread Philipp Kern
On Thu, Jan 17, 2008 at 02:38:45PM +, Steve Kemp wrote: > Felipe Sateler discovered that apt-listchanges, a package change history > notification tool, used unsafe paths when importing its python libraries. > This could allow the execution of arbitary shell commands if the root user > executed

Re: How about carrying this list on gmane?

2008-01-17 Thread Johannes Graumann
How am I supposed to guess that 'devel' refers to the general? Joh On Thursday 17 January 2008 13:13:27 Peter Jordan wrote: > Johannes Graumann, 01/17/08 13:07: > > See subject, > > > > Joh > > gmane.linux.debian.devel.security ??? -- Johannes Graumann, PhD Max-Planck-Institute of Biochemistr

Re: How about carrying this list on gmane?

2008-01-17 Thread Johannes Graumann
I forgot to say thanks ... Joh On Thursday 17 January 2008 13:13:27 Peter Jordan wrote: > Johannes Graumann, 01/17/08 13:07: > > See subject, > > > > Joh > > gmane.linux.debian.devel.security ??? signature.asc Description: This is a digitally signed message part.

Re: How about carrying this list on gmane?

2008-01-17 Thread Peter Jordan
Johannes Graumann, 01/17/08 13:07: > See subject, > > Joh gmane.linux.debian.devel.security ??? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

How about carrying this list on gmane?

2008-01-17 Thread Johannes Graumann
See subject, Joh signature.asc Description: This is a digitally signed message part.