bug #428770 (sic!) in sudo

2022-07-05 Thread Marc Haber
tings Marc -- - Marc Haber | "I don't trust Computers. They | Mailadresse im Header Leimen, Germany| lose things."Winona Ryder | Fon: *49 6224 1600402 Nordisch by Nature | How to make an American Quilt | Fax: *49 6224 1600421

Re: What is the best free HIDS for Debian

2022-05-04 Thread Marc Haber
id you read the fine README.Debian that comes with the aide package? Greetings Marc -- ----- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Leimen, Germany| lose things."

Re: HTTPS needs to be implemented for updating

2016-12-21 Thread Marc Haber
tically? Greetings Marc -- ----- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Leimen, Germany| lose things."Winona Ryder | Fon: *49 6224 1600402 Nordisch by Nature | How to make an American Quilt | Fax: *49 6224 1600421

Re: Security support incomplete? (was: Re: [SECURITY] [DSA 3455-1] curl security update)

2016-02-02 Thread Marc Haber
isturbed by this interpretation. Greetings Marc -- ----- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Leimen, Germany| lose things."Winona Ryder | Fon: *49 6224 1600402 Nordisch by Nature | How to make an American Quilt | Fax: *49 6224 1600421

Re: python 2.6.6 -> python 2.6.8

2012-06-25 Thread Marc Haber
Hi Henri, thanks for your explanation. On Mon, Jun 25, 2012 at 02:45:57PM +0300, Henri Salo wrote: > On Mon, Jun 25, 2012 at 09:49:08AM +0200, Marc Haber wrote: > > a colleague pointed me to the release notes of python 2.6.8, where the > > following security issues are lis

python 2.6.6 -> python 2.6.8

2012-06-25 Thread Marc Haber
rting those fixes? Greetings Marc -- - Marc Haber | "I don't trust Computers. They | Mailadresse im Header Mannheim, Germany | lose things."Winona Ryder | Fon: *49 621 31958061 Nordisch by Natu

Re: Long Exim break-in analysis

2010-12-26 Thread Marc Haber
as filed (#21941). This is too sad to comment any further. Greetings Marc -- ----- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Mannheim, Germany | lose things."Winona Ryder | Fon: *4

Re: Screensaver in KDE 4.2 (was: Random questions about KDE4.2)

2009-06-12 Thread Marc Haber
l seconds". This shouldn't happen. Greetings Marc -- ----- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Mannheim, Germany | lose things."Winona Ryder | Fon: *49 621 72739834 Nordisch by Nature |

Re: Vacation messages (was: Re: [SECURITY] [DSA 1629-1] New postfix packages fix privilege escalation)

2008-08-19 Thread Marc Haber
are bound to use broken software that sends out the broken vacation messages. Both major commercial groupware products on the market fail to do this properly. Greetings Marc -- ----- Marc Haber | "I don't tr

Re: Frustration with randome number generator vuln and ssh

2008-06-05 Thread Marc Haber
t; guess, is mostly used for the opposite case. It can, of course, be used to keep an older version installed as well. Greetings Marc -- ----- Marc Haber | "I don't trust Computers. They | Mailadresse im He

Re: Is oldstable security support duration something to be proud of?

2008-03-11 Thread Marc Haber
ave a point here. However, how would you do a fair comparision of security support? IMO, speed to release fixed versions should be taken into account as well. Greetings Marc -- ----- Marc Haber | "I don't

Re: Is oldstable security support duration something to be proud of?

2008-03-11 Thread Marc Haber
ainful as a reinstall away from us and towards Ubuntu LTS (if they want Debian technology) or to the commercial server variants. Greetings Marc -- - Marc Haber | "I don't trust Computers. They | Mailadresse im Header Mannheim, Germany | lose things."Winona Ryder | Fon:

Re: etchs aide messing logs

2007-07-15 Thread Marc Haber
to generate _LOTS_ of output, I'd like to advise you to reduce your aide config's complexity to the most simple setup that still shows your issues before debugging here. Let me know about your results, preferably using the BTS. Greetings Marc --

Re: OpenSSL vs. GnuTLS in Exim

2006-04-04 Thread Marc Haber
On Tue, Apr 04, 2006 at 01:37:24PM +0200, Florian Weimer wrote: > * Marc Haber: > > >> Is there any advantage of GnuTLS over OpenSSL ? > > > > GnuTLS' License fits better in Debian's freeness concept. > > Exim still links to OpenSSL, so I don't se

Re: OpenSSL vs. GnuTLS in Exim

2006-04-03 Thread Marc Haber
it exception in the GPLed software's license since openssl's license is incompatible with the GPL. We chose GnuTLS to avoid these license issues. Greetings Marc -- ----- Marc Haber | "I don't trust Com

Re: first A record of security.debian.org extremely slow

2006-03-03 Thread Marc Haber
arc -- ----- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Mannheim, Germany | lose things."Winona Ryder | Fon: *49 621 72739834 Nordisch by Nature | How to make an American Quilt | Fax: *49 621 72739835 -- To UNSUBSCRIBE, email t

Re: first A record of security.debian.org extremely slow

2006-03-02 Thread Marc Haber
On Thu, Mar 02, 2006 at 11:09:28PM +0100, Florian Weimer wrote: > * Marc Haber: > > How would you implement the automatism to trigger the update on the > > incoming e-mail? > > I typically use an Exim .forward file which invokes a special script > using "pipe".

Re: first A record of security.debian.org extremely slow

2006-03-02 Thread Marc Haber
er. Usually, cron-apt has already noticed that there is an update available before the DSA posting comes in. How would you implement the automatism to trigger the update on the incoming e-mail? Greetings Marc -- ----- Mar

Re: "Fix" of sudo with DSA-946-1

2006-01-29 Thread Marc Haber
know when I > should be watching various automated process more closely. Actually, cron-apt frequently picks up the updates before the DSA appears. Greetings Marc -- ----- Marc Haber | "I don't trust Co

Re: [SECURITY] [DSA 946-1] New sudo packages fix privilege escalation

2006-01-20 Thread Marc Haber
tems automatically, so it might be necessary to manually add this on stable and testing as well. Please advise. Thanks. Greetings Marc -- ----- Marc Haber | "I don't trust Computers. They | Mailadresse im

Re: What is a security bug?

2005-11-23 Thread Marc Haber
user, before it segfaults? Greetings Marc -- ----- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Mannheim, Germany | lose things."Winona Ryder | Fon: *49 621 72739834 Nordisch by Nature | How t

Re: On Mozilla-* updates

2005-07-30 Thread Marc Haber
in the security archive. I don't like the idea of shipping vulnerable software and not taking measures to prevent that software from being installed on a system with stable+security. We cannot expect our users to read our announcements. Greetings Marc -- -----

Re: using sarge on production machines

2005-02-18 Thread Marc Haber
(surprise), but more secure since security-related updates go into unstable immediately. > if only the security > team would start working *sigh*. afaik, the security team is ready, but the infrastructure is not. > >From: Marc Haber <[EMAIL PROTECTED]> > >It is bett

Re: using sarge on production machines

2005-02-18 Thread Marc Haber
On Fri, Feb 18, 2005 at 04:40:56AM -0800, Harry wrote: > --- Marc Haber <[EMAIL PROTECTED]> wrote: > > What does this gain you? A compomised uml is as bad as a compromised > > system. > > I can wipe the UML if the host has not been compromised. This saves me > a jou

Re: using sarge on production machines

2005-02-18 Thread Marc Haber
On Fri, Feb 18, 2005 at 02:25:17AM -0800, Harry wrote: > use UML and chroot it and run sarge in it. What does this gain you? A compomised uml is as bad as a compromised system. Greetings Marc -- ----- Marc Ha

Re: using sarge on production machines

2005-02-17 Thread Marc Haber
maybe hire somebody external to look after your systems. Greetings Marc -- ----- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Mannheim, Germany | lose things."Winona Ryder | Fon: *49 621 727398