Re: [SECURITY] [DSA 3449-1] bind9 security update

2016-01-20 Thread Ronald Schmidt
unsubscribe Salvatore Bonaccorso schrieb am Di., 19. Jan. 2016 um 21:45 Uhr: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > - - > Debian Security Advisory DSA-3449-1 secur...@debian.org > https://w

Re: stalin: CVE-2015-8697: Insecure use of temporary files

2016-01-20 Thread Salvatore Bonaccorso
Hi Rob, On Wed, Jan 20, 2016 at 05:41:56AM -0600, Rob Browning wrote: > Rob Browning writes: > > > I believe the package is scheduled to be removed next week, and I'm > > still waiting on a discussion with upstream about a (non-trivial) patch > > I wrote to attempt to address the problem. > > >

Re: stalin: CVE-2015-8697: Insecure use of temporary files

2016-01-20 Thread Rob Browning
Rob Browning writes: > I believe the package is scheduled to be removed next week, and I'm > still waiting on a discussion with upstream about a (non-trivial) patch > I wrote to attempt to address the problem. > > So I wanted to ask for an opinion about the claim here that it might be > reasonabl

Re: [SECURITY] [DSA 3448-1] linux security update

2016-01-20 Thread Holger Levsen
Hi, On Mittwoch, 20. Januar 2016, Bjoern Nyjorden wrote: > Most appreciated. So, just to confirm; my take away on this is: > > * 1. "Wheezy" Linux kernels are NOT AFFECTED. > > * 2. "Wheezy" & "Jessie" BACKPORTS Linux kernels are VUNERABLE. > > If I have understood correctly? yes! cheer