Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Peter Palfrader
On Wed, 13 Apr 2016, Bjoern Nyjorden wrote: > Given that this is not the first occurrence, I think it is, actually. As often is the case in the swiss-cheese model, here all the holes lined up and the update of this security mirror was delayed for about two days. We can identify at least four ca

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Bjoern Nyjorden
Free as in "freedom" operating systems, and a free-ish and open internet are global, vital and empowering assets that I guess a lot of us tend to take for granted. Keep up the good work. I hope to be in a better position in the future, to have something worthwhile to contribute to the Debian,

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Bjoern Nyjorden
Hi again, Yes, as at ~ 0810 +0800 (0010 UTC) today; the server address below was resolving to the IP Address that you correctly assumed: URI: http://security.debian.org/debian-security/pool/updates/main/i/imagemagick/ IP Address: 150.203.164.61 (at my Australian location). The imagemagi

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Adam D. Barratt
On Wed, 2016-04-13 at 13:21 +0800, Bjoern Nyjorden wrote: > * 1. Although my inbox has the time stamp of 19:50 +0800 (12:50 > +0100); the email below did not show up in my inbox until 23:40 +0800 > (16:40 +0100) - the time my ISP reports receiving the mail. It > certainly was not in my inbox

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Bjoern Nyjorden
Hi Adam, The reason there has been a delay in my reply to your email below: * 1. Although my inbox has the time stamp of 19:50 +0800 (12:50 +0100); the email below did not show up in my inbox until 23:40 +0800 (16:40 +0100) - the time my ISP reports receiving the mail. It certainly was not

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Peter Palfrader
On Tue, 12 Apr 2016, Michael Stone wrote: > On Tue, Apr 12, 2016 at 08:56:35PM -0300, Henrique de Moraes Holschuh wrote: > >Then, maybe we should consider a better way to deal with areas where you > >get only one choice out of geoip? > > Reach out to the relevant team outlining your issues (e.g.,

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Michael Stone
On Tue, Apr 12, 2016 at 08:56:35PM -0300, Henrique de Moraes Holschuh wrote: Then, maybe we should consider a better way to deal with areas where you get only one choice out of geoip? Reach out to the relevant team outlining your issues (e.g., lack of IPv6 connectivity)? Advising people to har

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Henrique de Moraes Holschuh
On Tue, Apr 12, 2016, at 16:47, Peter Palfrader wrote: > On Tue, 12 Apr 2016, Henrique de Moraes Holschuh wrote: > > > We list several mirrors carrying debian security updates in > > https://www.debian.org/mirror/list-full > > I think we shouldn't. Well, we do, regardless of whether we should o

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Henrique de Moraes Holschuh
On Tue, Apr 12, 2016, at 16:37, Michael Stone wrote: > On Tue, Apr 12, 2016 at 04:19:20PM -0300, Henrique de Moraes Holschuh > wrote: > >We don't disclose which mirrors are members of the security.debian.org > >pool anywhere (that I could find), so we are currently hiding everything > >behind sec

Call for testing: upcoming samba security update

2016-04-12 Thread Salvatore Bonaccorso
Hi The upcoming Samba update is bigger than usual since for Jessie an update is needed to 4.2. We want to expose the package a bit more for additional testing. Please test the packages found on https://people.debian.org/~carnil/tmp/samba/ (no apt repository available for these test packa

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Peter Palfrader
On Tue, 12 Apr 2016, Henrique de Moraes Holschuh wrote: > We list several mirrors carrying debian security updates in > https://www.debian.org/mirror/list-full I think we shouldn't. > We don't disclose which mirrors are members of the security.debian.org https://anonscm.debian.org/cgit/mirror/d

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Michael Stone
On Tue, Apr 12, 2016 at 04:19:20PM -0300, Henrique de Moraes Holschuh wrote: We don't disclose which mirrors are members of the security.debian.org pool anywhere (that I could find), so we are currently hiding everything behind security.debian.org. This wasn't a problem when a DNS lookup for secu

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Henrique de Moraes Holschuh
On Tue, Apr 12, 2016, at 14:32, Peter Palfrader wrote: > On Tue, 12 Apr 2016, Henrique de Moraes Holschuh wrote: > > On Tue, Apr 12, 2016, at 14:06, Adam D. Barratt wrote: > > > Judging from your e-mail address, I'm going to assume that the answer is > > > that security.debian.org resolved to 150.

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Peter Palfrader
On Tue, 12 Apr 2016, Henrique de Moraes Holschuh wrote: > On Tue, Apr 12, 2016, at 14:06, Adam D. Barratt wrote: > > Judging from your e-mail address, I'm going to assume that the answer is > > that security.debian.org resolved to 150.203.164.61. > > > > Apparently there was an issue with syncin

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Henrique de Moraes Holschuh
On Tue, Apr 12, 2016, at 14:06, Adam D. Barratt wrote: > Judging from your e-mail address, I'm going to assume that the answer is > that security.debian.org resolved to 150.203.164.61. > > Apparently there was an issue with syncing to that mirror. The sysadmin > team have triggered a manual sync

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Adam D. Barratt
On 2016-04-12 16:35, Adam D. Barratt wrote: On 2016-04-12 15:42, Bjoern Nyjorden wrote: Hi Luciano and others, AS AT: 2230(+0800) (1430(+)): * Imagemagick version 8:6.7.7.10-5+deb7u4 is STILL NOT AVAILABLE at: http://security.debian.org/debian-security/pool/updates/main/i/imagemagic

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Drake Wilson
Bjoern Nyjorden wrote: > Hi Luciano and others, > > AS AT: 2230(+0800) (1430(+)): > > * Imagemagick version 8:6.7.7.10-5+deb7u4 is STILL NOT AVAILABLE at: > > > http://security.debian.org/debian-security/pool/updates/main/i/imagemagick/ They look good to me at the moment (2016-04-12T15:

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Adam D. Barratt
On 2016-04-12 15:42, Bjoern Nyjorden wrote: Hi Luciano and others, AS AT: 2230(+0800) (1430(+)): * Imagemagick version 8:6.7.7.10-5+deb7u4 is STILL NOT AVAILABLE at: http://security.debian.org/debian-security/pool/updates/main/i/imagemagick/ * Aptitude (or apt-get) is unable to upda

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Bjoern Nyjorden
Hi Luciano and others, AS AT: 2230(+0800) (1430(+)): * Imagemagick version 8:6.7.7.10-5+deb7u4 is STILL NOT AVAILABLE at: http://security.debian.org/debian-security/pool/updates/main/i/imagemagick/ * Aptitude (or apt-get) is unable to update as a result Can you please ensure that th

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Luciano Bello
On Tuesday 12 April 2016 19.21.57 Bjoern Nyjorden wrote: > Imagemagick version 8:6.7.7.10-5+deb7u4 is STILL NOT AVAILABLE at the > http://security.debian.org/ server. > > I'm very concerned about this. Will the updated version be uploaded soon? It should be now. It appears in https://tracker.d

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Adam D. Barratt
On 2016-04-12 12:21, Bjoern Nyjorden wrote: Hi again, Imagemagick version 8:6.7.7.10-5+deb7u4 is STILL NOT AVAILABLE at the http://security.debian.org/ server. I'm very concerned about this. Will the updated version be uploaded soon? What IP address does security.debian.org resolve to for

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-12 Thread Bjoern Nyjorden
Hi again, Imagemagick version 8:6.7.7.10-5+deb7u4 is STILL NOT AVAILABLE at the http://security.debian.org/ server. I'm very concerned about this. Will the updated version be uploaded soon? Yours sincerely, Bjoern. On 12/04/16 03:12, Luciano Bello wrote: -BEGIN PGP SIGNED MESSAGE