Re: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail (fwd)

2003-03-04 Thread Denis A. Kulgeyko
> I'd just like to say something. I began this thread purely because I > didn't see Debian listed in the CERT advisory. So let me be clear about > some things: Sorry for some offtopic. My english isn't excellent and so may be that You misunderstood me. I'm using Debian more than 3 years and

Re: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail (fwd)

2003-03-04 Thread Ramon Kagan
I'd just like to say something. I began this thread purely because I didn't see Debian listed in the CERT advisory. So let me be clear about some things: 1. I was not ragging on Debian. 2. Debian as a organization does an amazing job and gets way too much criticism. If you don't have anything

Re: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail (fwd)

2003-03-04 Thread Denis A. Kulgeyko
> I'd just like to say something. I began this thread purely because I > didn't see Debian listed in the CERT advisory. So let me be clear about > some things: Sorry for some offtopic. My english isn't excellent and so may be that You misunderstood me. I'm using Debian more than 3 years and

Re: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail (fwd)

2003-03-04 Thread Denis A. Kulgeyko
Hi, All ! As I see, at this moment we have update for sendmail for "woody" (for "potato" i not checked). :) So, Debian was vulnerable too (nothing strange, it must be). Damn, now i must replace just updated (by me, from sources) sendmails by updated Debian packages. ;) But that's not a prob

Re: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail(fwd)

2003-03-04 Thread Ramon Kagan
I'd just like to say something. I began this thread purely because I didn't see Debian listed in the CERT advisory. So let me be clear about some things: 1. I was not ragging on Debian. 2. Debian as a organization does an amazing job and gets way too much criticism. If you don't have anything

Re: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail (fwd)

2003-03-04 Thread Denis A. Kulgeyko
Hi, All ! As I see, at this moment we have update for sendmail for "woody" (for "potato" i not checked). :) So, Debian was vulnerable too (nothing strange, it must be). Damn, now i must replace just updated (by me, from sources) sendmails by updated Debian packages. ;) But that's not a prob

Re: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail (fwd)

2003-03-03 Thread Rich Puhek
Vassilii Khachaturov wrote: (See also the bugs from the CC). I believe that Debian should be somehow put on the CERT vendor list: they give the vendors more advance warning on the security issues before they issue an advisory, allowing to issue an emergency patch. Does anybody on this list (debi

Re: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail (fwd)

2003-03-03 Thread Rich Puhek
Vassilii Khachaturov wrote: (See also the bugs from the CC). I believe that Debian should be somehow put on the CERT vendor list: they give the vendors more advance warning on the security issues before they issue an advisory, allowing to issue an emergency patch. Does anybody on this list (debian-

RE: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail ( fwd)

2003-03-03 Thread Jones, Steven
Debian systems tend to use Exim by default? my installs certainly do. Mind you I remove it and install Sendmail usually as its our "standard". So Im a we bit concerned. No updates from security.debian as of 2:00AM NZT. Im not blaming Debian ppl here of being slow or anything, they do a fine job of

Re: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail (fwd)

2003-03-03 Thread Vassilii Khachaturov
(See also the bugs from the CC). I believe that Debian should be somehow put on the CERT vendor list: they give the vendors more advance warning on the security issues before they issue an advisory, allowing to issue an emergency patch. Does anybody on this list (debian-security) have any ties wit

RE: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail (fwd)

2003-03-03 Thread Jones, Steven
Debian systems tend to use Exim by default? my installs certainly do. Mind you I remove it and install Sendmail usually as its our "standard". So Im a we bit concerned. No updates from security.debian as of 2:00AM NZT. Im not blaming Debian ppl here of being slow or anything, they do a fine job of

Re: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail (fwd)

2003-03-03 Thread Vassilii Khachaturov
(See also the bugs from the CC). I believe that Debian should be somehow put on the CERT vendor list: they give the vendors more advance warning on the security issues before they issue an advisory, allowing to issue an emergency patch. Does anybody on this list (debian-security) have any ties wit