Re: [DNG] exim4 packages 4.92-8+deb10u6 in beowulf-security?

2021-05-06 Thread Thomas Besser via Dng
Am 06.05.21 um 20:53 schrieb Ludovic Bellière: You mean this[1] package? [1]: https://pkginfo.devuan.org/cgi-bin/package-query.html?c=package&q=exim4=4.92-8+deb10u6 It's a platform independent ('all') package. Look at https://pkginfo.devuan.org/cgi-bin/policy-query.html?c=package&q=exim4-ba

Re: [DNG] ..are we|Devuan safe from this systemd backdoor malware, taking our kernels from Debian?

2021-05-06 Thread Rick Moen
Quoting marc (marc...@welz.org.za): > > > > > >> https://www.theregister.com/2021/04/29/stealthy_linux_backdoor_malware_spotted/ > > >> > > > ..how it works: > > > https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en/ > > > > > > This backdoor is targetting systemd and gvfs. > > So the

Re: [DNG] ..are we|Devuan safe from this systemd backdoor malware, taking our kernels from Debian?

2021-05-06 Thread Rick Moen
Quoting Dr. Nikolaus Klepp (off...@klepp.biz): > And there's alway the possibillity of 3rd party software, e.g. Teams, > Appimages, ... Always. Looking from a distro-management perspective, doing that falls into the broad category of "User circumvents the distro's management regime", and natural

Re: [DNG] ..are we|Devuan safe from this systemd backdoor malware, taking our kernels from Debian?

2021-05-06 Thread marc
> > > >> https://www.theregister.com/2021/04/29/stealthy_linux_backdoor_malware_spotted/ > >> > > ..how it works: > > https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en/ > > > This backdoor is targetting systemd and gvfs. So the below words aren't directed at anybody in particular: I

Re: [DNG] exim4 packages 4.92-8+deb10u6 in beowulf-security?

2021-05-06 Thread Ludovic Bellière
You mean this[1] package? [1]: https://pkginfo.devuan.org/cgi-bin/package-query.html?c=package&q=exim4=4.92-8+deb10u6 On jeu, 06 mai 2021, Thomas Besser via Dng wrote: > Hi, > > asked this already in IRC on #devuan, but perhaps some devs are reading this > here. > > Fixing 21Nails > (https:/

[DNG] exim4 packages 4.92-8+deb10u6 in beowulf-security?

2021-05-06 Thread Thomas Besser via Dng
Hi, asked this already in IRC on #devuan, but perhaps some devs are reading this here. Fixing 21Nails (https://blog.qualys.com/vulnerabilities-research/2021/05/04/21nails-multiple-vulnerabilities-in-exim-mail-server) in exim4 seems to be urgent. Debian buster-security has already exim4 4.9