Really keen to get more information?

2010-11-15 Thread Brian Thomas
Fifty extremely 'fortunate' people are required to preview the best business that has launched in the last ten years. You won't be asked to spend any money, just take a look at the business and give us your professional feedback on the idea and profitability. Would you like to secure the mythical

Re: CVE-2009-3555 not addressed in OpenSSL

2010-11-15 Thread Stefan Fritsch
On Thursday 11 November 2010, Kurt Roeckx wrote: > So I've prepared a package based on the ubuntu patch. I also went > over every commit between the 0.9.8l and 0.9.8m release and am > reasonly confident this patch should work properly. > > The current package is available at: > http://people.debi

Re: ProFTPD IAC Remote Root Exploit

2010-11-15 Thread Adrian Minta
On 11/15/10 18:41, Sven Hoexter wrote: On Mon, Nov 15, 2010 at 06:15:48PM +0200, Adrian Minta wrote: Any debian reaction on this ? http://seclists.org/fulldisclosure/2010/Nov/49 It doesn't effect the version shipped with Lenny and is fixed in testing and unstable. http://bugs.proftpd

Re: ProFTPD IAC Remote Root Exploit

2010-11-15 Thread Sven Hoexter
On Mon, Nov 15, 2010 at 06:15:48PM +0200, Adrian Minta wrote: > Any debian reaction on this ? > http://seclists.org/fulldisclosure/2010/Nov/49 It doesn't effect the version shipped with Lenny and is fixed in testing and unstable. http://bugs.proftpd.org/show_bug.cgi?id=3521 http://bugs.debian.org

Re: ProFTPD IAC Remote Root Exploit

2010-11-15 Thread Adam D. Barratt
On Mon, November 15, 2010 16:15, Adrian Minta wrote: > Any debian reaction on this ? > http://seclists.org/fulldisclosure/2010/Nov/49 This is CVE-2010-4221. It's been fixed in unstable and testing since before the post you reference was made, and doesn't affect stable. Regards, Adam -- To UN

ProFTPD IAC Remote Root Exploit

2010-11-15 Thread Adrian Minta
Any debian reaction on this ? http://seclists.org/fulldisclosure/2010/Nov/49 -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/4ce15cb4.5070...@gmail.com

Re: [SECURITY] [DSA 2038-3] New pidgin packages fix regression

2010-11-15 Thread Michael Gilbert
On Mon, 15 Nov 2010 13:59:01 +0100, Gerfried Fuchs wrote: > Hi! > > * Thijs Kinkhorst [2010-11-15 13:32:16 CET]: > > On Mon, November 15, 2010 12:24, Gerfried Fuchs wrote: > > > * Thijs Kinkhorst [2010-11-13 20:37:28 CET]: > > >> Since a few months, Microsoft's servers for MSN have chang

Re: [SECURITY] [DSA 2038-3] New pidgin packages fix regression

2010-11-15 Thread Gerfried Fuchs
Hi! * Thijs Kinkhorst [2010-11-15 13:32:16 CET]: > On Mon, November 15, 2010 12:24, Gerfried Fuchs wrote: > > * Thijs Kinkhorst [2010-11-13 20:37:28 CET]: > >> Since a few months, Microsoft's servers for MSN have changed the > >> protocol, > >> making Pidgin non-functional for use with M

Re: [SECURITY] [DSA 2038-3] New pidgin packages fix regression

2010-11-15 Thread Thijs Kinkhorst
Hi Gerfried, On Mon, November 15, 2010 12:24, Gerfried Fuchs wrote: > Hi! > > * Thijs Kinkhorst [2010-11-13 20:37:28 CET]: >> Since a few months, Microsoft's servers for MSN have changed the >> protocol, >> making Pidgin non-functional for use with MSN. It is not feasible to >> port >> th

Re: [SECURITY] [DSA 2038-3] New pidgin packages fix regression

2010-11-15 Thread Gerfried Fuchs
Hi! * Thijs Kinkhorst [2010-11-13 20:37:28 CET]: > Since a few months, Microsoft's servers for MSN have changed the protocol, > making Pidgin non-functional for use with MSN. It is not feasible to port > these changes to the version of Pidgin in Debian Lenny. This update > formalises that