Re: [SECURITY] [DSA 1680-1] New clamav packages fix potential codeexecution

2008-12-11 Thread Mapper ict department
It works for me now. The update appeared in the upgradeable packages and was updated without a problem (came from the volatile main pool) I guess they fixed it OR they were a little late putting the updates in the contents file OR they were a little early announcing the 0.94.dfsg.2-1 was there. -

Re: [SECURITY] [DSA 1681-1] New Linux 2.6.24 packages fix several vulnerabilities

2008-12-11 Thread dann frazier
On Thu, Dec 11, 2008 at 05:06:52PM +, Dominic Hargreaves wrote: > On Thu, Dec 04, 2008 at 10:59:11AM -0700, dann frazier wrote: > > > Package: linux-2.6.24 > > Vulnerability : denial of service/privilege escalation > > Problem type : local/remote > > Debian-specific: no > > CVE Id(s

Re: [SECURITY] [DSA 1681-1] New Linux 2.6.24 packages fix several vulnerabilities

2008-12-11 Thread dann frazier
On Thu, Dec 11, 2008 at 06:49:59PM +, Dominic Hargreaves wrote: > On Thu, Dec 11, 2008 at 11:38:28AM -0700, dann frazier wrote: > > Yes - 2.6.18 is in stable, and as such will be security supported for > > at least another year. Minor/local DoS security issues in the kernel > > are very frequen

Re: [SECURITY] [DSA 1681-1] New Linux 2.6.24 packages fix several vulnerabilities

2008-12-11 Thread Dominic Hargreaves
On Thu, Dec 11, 2008 at 12:11:05PM -0700, dann frazier wrote: > On Thu, Dec 11, 2008 at 06:49:59PM +, Dominic Hargreaves wrote: > > May I make a suggestion that you include a comment along these lines in > > the advisory texts? It would help reassure users that things haven't been > > forgotte

Re: [SECURITY] [DSA 1681-1] New Linux 2.6.24 packages fix several vulnerabilities

2008-12-11 Thread Dominic Hargreaves
On Thu, Dec 11, 2008 at 11:38:28AM -0700, dann frazier wrote: > Yes - 2.6.18 is in stable, and as such will be security supported for > at least another year. Minor/local DoS security issues in the kernel > are very frequent, so updated packages are constantly in > preparation. Preparing kernel upd

Re: [SECURITY] [DSA 1681-1] New Linux 2.6.24 packages fix several vulnerabilities

2008-12-11 Thread Dominic Hargreaves
On Thu, Dec 04, 2008 at 10:59:11AM -0700, dann frazier wrote: > Package: linux-2.6.24 > Vulnerability : denial of service/privilege escalation > Problem type : local/remote > Debian-specific: no > CVE Id(s) : CVE-2008-3528 CVE-2008-4554 CVE-2008-4576 CVE-2008-4618 >

Re: [VUA 51-1] Updated clamav version

2008-12-11 Thread Andreas Barth
* Jim Popovitch ([EMAIL PROTECTED]) [081211 07:52]: > On Thu, Dec 11, 2008 at 00:55, Andreas Barth <[EMAIL PROTECTED]> wrote: > > --- > > Debian Volatile Update Announcement VUA 51-1 http://volatile.debian.org > > [EMAIL PR