Re: Missing public key -- Re: [SECURITY] [DSA 1835-1] New tiff packages fix several vulnerabilities

2009-07-15 Thread aliceinwire
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Lukas Faulstich wrote: > apt-get was not able to authenticate the security updates from DSA-1835-1 > due to a missing public key (see Listing 1 below). Furthermore, I was not > able to verify the security advisory because I could not connect to > keyri

Re: Missing public key -- Re: [SECURITY] [DSA 1835-1] New tiff packages fix several vulnerabilities

2009-07-15 Thread Michel Messerschmidt
On Thu, Jul 16, 2009 at 12:41:32AM +0200, Lukas Faulstich wrote: > W: GPG error: http://security.debian.org etch/updates Release: Die > folgenden Signaturen konnten nicht überprüft werden, weil ihr öffentlicher > Schlüssel nicht verfügbar ist: NO_PUBKEY 9AA38DCD55BE302B > W: Probieren Sie »apt-get

Missing public key -- Re: [SECURITY] [DSA 1835-1] New tiff packages fix several vulnerabilities

2009-07-15 Thread Lukas Faulstich
apt-get was not able to authenticate the security updates from DSA-1835-1 due to a missing public key (see Listing 1 below). Furthermore, I was not able to verify the security advisory because I could not connect to keyring.debian.org, although I was able to ping it, see Listing 2 below. How shoul

[SEC#LVW-YnCMb-005] [SECURITY] [DSA 1834-1] New apache2 packages fix denial of service

2009-07-15 Thread Dan Bassett
Updated on arachnae and stantz. Dan

Re: [SECURITY] [DSA 1833-1] New dhcp3 packages fix arbitrary code execution

2009-07-15 Thread Celejar
On Tue, 14 Jul 2009 21:33:29 +0200 Florian Weimer wrote: ... > Several remote vulnerabilities have been discovered in ISC's DHCP > implementation: > > It was discovered that dhclient does not properly handle overlong > subnet mask options, leading to a stack-based buffer overflow and > possible

Re: http://www.debian.org/security/ does not show dsa-1753-2

2009-07-15 Thread Simon Paillard
Hello Thieo (and security team) On Wed, Jul 15, 2009 at 02:55:19PM +0200, Thiemo Nagel wrote: > I just noticed that dsa-1753-2 (icedove end-of-life) is not displayed on > http://www.debian.org/security/, although it is merely 3 days old (from > July 12)... You're right, thanks for your notice