Testers needed for ghostscript update

2018-09-03 Thread Moritz Mühlenhoff
There's a number of vulnerabilities found in Ghostscript by Tavis Ormandy. His research is still ongoing with new issues being found, but I've created an interim update which addresses most of the recent issues he found. It works fine in my tests, but my use case is fairly limited (printing via a l

Status of security support in Debian stable

2018-09-03 Thread jaroslav
Hello, I would like to ask about the status of security support for LAMP packages in Debian stable. I've noticed that security related updates have been lagging behind upstream - for example PHP security updates from Debian usually come out few weeks or even months after upstream release. Whe

Re: Hardening Linux conf

2018-09-03 Thread Bastian Blank
[replying to you also] On Mon, Sep 03, 2018 at 12:48:53PM +0200, Tomas Bortoli wrote: > It allows to quickly find weak spots in Linux configs. Running it against: > https://salsa.debian.org/kernel-team/linux/blob/master/debian/config/config This is not the config of the Debian kernel. And if you

Hardening Linux conf

2018-09-03 Thread Tomas Bortoli
Hi, I've recently discovered this interesting resource: https://a13xp0p0v.github.io/2018/07/07/kconfig-hardened-check.html It allows to quickly find weak spots in Linux configs. Running it against: https://salsa.debian.org/kernel-team/linux/blob/master/debian/config/config That, AFAIK is the off