Re: [SECURITY] [DSA 3148-1] chromium-browser end of life

2015-02-01 Thread Michael Gilbert
On Sun, Feb 1, 2015 at 9:52 PM, Russell Coker wrote: > On Sun, 1 Feb 2015 11:18:43 PM Paul Wise wrote: >> chromium was already being backported to wheezy for security updates, >> the latest versions need newer compilers so we can't backport any >> more. > > Why can't we backport the compilers too?

Re: [SECURITY] [DSA 3148-1] chromium-browser end of life

2015-02-01 Thread Paul Wise
On Mon, Feb 2, 2015 at 10:52 AM, Russell Coker wrote: > Why can't we backport the compilers too? I think you meant to send this question to t...@security.debian.org and debian-rele...@lists.debian.org. -- bye, pabs https://wiki.debian.org/PaulWise -- To UNSUBSCRIBE, email to debian-security

Re: [SECURITY] [DSA 3148-1] chromium-browser end of life

2015-02-01 Thread Russell Coker
On Sun, 1 Feb 2015 11:18:43 PM Paul Wise wrote: > chromium was already being backported to wheezy for security updates, > the latest versions need newer compilers so we can't backport any > more. Why can't we backport the compilers too? -- To UNSUBSCRIBE, email to debian-security-requ...@lists.

Re: [SECURITY] [DSA 3148-1] chromium-browser end of life

2015-02-01 Thread Paul Wise
On Mon, Feb 2, 2015 at 3:14 AM, Pavlos K. Ponos wrote: > Since the latest gcc version for Wheezy is the 4.7 and Chromium "moves" to > 4.8, what shall we do? Follow the advice in DSA-3148-1: upgrade to jessie or switch to the iceweasel web browser. > Till the next stable release (Jessie), are we

Re: [SECURITY] [DSA 3148-1] chromium-browser end of life

2015-02-01 Thread Pavlos K. Ponos
Hello, Since the latest gcc version for Wheezy is the 4.7 and Chromium "moves" to 4.8, what shall we do? Till the next stable release (Jessie), are we vulnerable to security issues? As mentioned before, we can build environments to support all the upstream features but this goes against the "s

Re: are unattended updates a good idea?

2015-02-01 Thread ge...@riseup.net
On 15-01-31 09:58:39, Ml Ml wrote: > i have got about 50 Debian 6+7 Servers. They are doing all kind of > things like Webserver, Mailserver, DNS, etc… > > I am using apticron to keep track of the updates, but i seem to use > more and more time updating the hosts. > > [...] > > Is anyone else facin

Re: are unattended updates a good idea?

2015-02-01 Thread Will Aoki
On Sat, Jan 31, 2015 at 09:58:39AM +0100, Ml Ml wrote: > Is anyone else facing the same problem? What are your experiences > doing (blind) automatic security updates. I've done automatic updates for Debian under cfengine control for nine years and Ubuntu for perhaps one and a half. I started with

Re: Debian Live CD - unsecured ssh open by default

2015-02-01 Thread John Goerzen
Great news, thanks! On 01/31/2015 07:01 PM, Evgeny Kapun wrote: > This should be fixed in the latest version. See > https://bugs.debian.org/741678. > > On 01.02.2015 03:09, John Goerzen wrote: >> Hello, >> >> A friend of mine pointed out to me recently that the Debian Live CD has >> ssh open to t