Re: Please clarifiy: kernel-sources / ptracebug / debian security announcenments

2003-05-09 Thread Jon
On Thu, 2003-05-08 at 10:54, Oliver Hitz wrote: > On 08 May 2003, Markus Kolb wrote: > > > There are patched Debian kernel images with version 2.4.18-7 by the > > kernel-image maintainer Herbet Xu but not in official debian package > > trees. Just don't know where to find Herbert's packages. Per

Re: Please clarifiy: kernel-sources / ptracebug / debian security announcenments

2003-05-09 Thread Jon
On Fri, 2003-05-09 at 00:27, Jon wrote: > Sources are patched as of woody.2, according to this changes file[1], > but only woody.1 images are available[2], as far as I can tell. The > images at the second URL are still vulnerable: > > [1]http://ftp.debian.org/dists/proposed-updates/kernel-source

Re: Strange Load Average patterns

2003-05-09 Thread Jan Eringa
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Rudolph, I had a similar problem at one stage I had the syslogd set up to forward everything to a loghost But I forgot an old entry in the /etc/hosts that was pointing to the localhost It showed up as HUGE log files in /var/log and high LA's

ptrace fix in 2.4

2003-05-09 Thread Adam ENDRODI
Hi - Yesterday Bernhard Kaindl committed a cleanup patch addressing numerous problems encountered with the original ptrace fix. Now it should be in -rc2. For more information and diffs, see http://linux.bkbits.net:8080/linux-2.4/[EMAIL PROTECTED]|[EMAIL PROTECTED] and http://linux.bkbits.net:80

Re: chattr +a in /var/log files

2003-05-09 Thread Victor Calzado Mayo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi from .es where everything else is a joke too :PP On Thursday 08 May 2003 21:44, Juan Carlos Silla. wrote: > Hello *: > > I would like set 'a' bit for files in /var/log/ but it makes > imposible to logrotate to rotate log files normaly. Is e

Re: trojan horse on testing?

2003-05-09 Thread Noah Meyerhans
On Fri, May 09, 2003 at 08:34:16PM +0200, tomas pospisek wrote: > > Packages that have security relevant bugs in testing could be kicked > ___immediately___ out of testing. What do people think? That wouldn't help anything. People would have already installed the vulnerable package. apt-get wou