CVS server in a user-mode-linux

2003-12-19 Thread Bill Allombert
Hello Debian-security list, I have experimented with running an anonymous CVS server inside user-mode-linux. So far this seems to work well and hopefully should enhance security a bit. The host kernel has the skas patch. I use hostfs to mount only the repositories inside the UML. I have limited t

CVS server in a user-mode-linux

2003-12-19 Thread Bill Allombert
Hello Debian-security list, I have experimented with running an anonymous CVS server inside user-mode-linux. So far this seems to work well and hopefully should enhance security a bit. The host kernel has the skas patch. I use hostfs to mount only the repositories inside the UML. I have limited t

Re: security audit of package toppler

2003-11-11 Thread Bill Allombert
[Sorry I missed your answer...] > On Tue, Nov 04, 2003 at 12:14:47AM +0100, Bill Allombert wrote: > > > So, I would like to know if one of you is willing to review toppler. > > I had a look at the two versions to hand, toppler 0.96 in stable, > and toppler-1.0.3 in unstab

Re: security audit of package toppler

2003-11-11 Thread Bill Allombert
[Sorry I missed your answer...] > On Tue, Nov 04, 2003 at 12:14:47AM +0100, Bill Allombert wrote: > > > So, I would like to know if one of you is willing to review toppler. > > I had a look at the two versions to hand, toppler 0.96 in stable, > and toppler-1.0.3 in unstab

security audit of package toppler

2003-11-03 Thread Bill Allombert
Dear Debian security, There were talk back in August of people willing to perform security audit of packages including set[ug]id binaries. So, I would like to know if one of you is willing to review toppler. Toppler could be made setgid games, but this was disabled with security concern with olde

security audit of package toppler

2003-11-03 Thread Bill Allombert
Dear Debian security, There were talk back in August of people willing to perform security audit of packages including set[ug]id binaries. So, I would like to know if one of you is willing to review toppler. Toppler could be made setgid games, but this was disabled with security concern with olde