Author: pollux Date: 2012-03-03 12:39:42 +0000 (Sat, 03 Mar 2012) New Revision: 18577 Modified: hardening/subgoal-daemons.txt hardening/subgoal-interpreters.txt Log: Update list of hardened packages for network daemons and interpreters Modified: hardening/subgoal-daemons.txt ==================================================================--- hardening/subgoal-daemons.txt 2012-03-03 11:05:42 UTC (rev 18576) +++ hardening/subgoal-daemons.txt 2012-03-03 12:39:42 UTC (rev 18577) @@ -20,7 +20,6 @@ ample amule and -apt-cacher-ng archfs asterisk at @@ -118,7 +117,6 @@ kerneloops keynav klone -krb5 krb5-appl labrea ldm-server @@ -153,7 +151,6 @@ mysql-5.1 nagios3 nas -nbd net-acct net-snmp netatalk @@ -161,7 +158,6 @@ nfdump nfs-utils ngetty -nginx ngircd notification-daemon notify-osd @@ -176,7 +172,6 @@ p910nd pacemaker pads -pcsc-lite pommed portsentry postfix-gld @@ -206,11 +201,7 @@ slony1-2 smcroute snmptrapfmt -solid-pop3d -squid -squid3 squidguard -sslh stunnel4 sup swapspace @@ -273,7 +264,6 @@ cron (uses dh compat 7) isc-dhcp (#644413) sniffit (#649817) -vsftpd (#644295) w3m (patch committed: http://anonscm.debian.org/gitweb/?p=collab-maint/w3m.git;a=commitdiff;h=f7218d492169d5d863427dc8f12fceecab68e31c) radvd (#644614, uses cdbs so next upload should add this) @@ -281,20 +271,35 @@ aiccu (#644408, pending) Resolved/fixed: -apache2 (>= 2.2.12-1, sometimes partial) +apache2 2.2.12-1, sometimes partial +apt-cacher-ng 0.6.12-1 avahi -lighttpd (>= 1.4.30-1) -bind9 (>= 1:9.5.0.dfsg.P2-2) -loqui (>= 0.5.1-2) -nagios-plugins (>= 1.4.15-5) -openldap (>= 2.4.25-4 #644427) -postfix (>= 2.5.4-2) -openssh (>= 1:5.2p1-1) -xdm 1:1.1.11-1 -rsyslog (=> 5.8.6-1 #644303) -tcpdump (=> 4.0.0-6) -fetchmail (>= 6.3.21-3) -inetutils 2:1.9-1 +bind9 1:9.5.0.dfsg.P2-2 +fetchmail 6.3.21-3 +inetutils 2:1.9-1 +krb5 1.10+dfsg~beta1-1 #655248 +lighttpd 1.4.30-1 +loqui 0.5.1-2 +memcachedb 1.2.0-9 +nagios-plugins 1.4.15-5 +nbd 1:3.0-1 +nginx 1.1.14-1 +openldap 2.4.25-4 #644427 +openssh 1:5.2p1-1 +openvpn 2.2.1-4 +pcsc-lite 1.8.2-1 +postfix 2.5.4-2 +rsyslog 5.8.6-1 #644303 +solid-pop3d 0.15-25 +squid 2.7.STABLE7-1 +squid3 partial +sslh 1.10-1 +suricata 1.0-1 +tcpdump 4.0.0-6 +tinyproxy 1.8.3-2 +trousers 0.3.8-1 +vsftpd 2.3.5-2 #644295 +xdm 1:1.1.11-1 Modified: hardening/subgoal-interpreters.txt ==================================================================--- hardening/subgoal-interpreters.txt 2012-03-03 11:05:42 UTC (rev 18576) +++ hardening/subgoal-interpreters.txt 2012-03-03 12:39:42 UTC (rev 18577) @@ -78,13 +78,15 @@ yorick Candidates: -bash (#641350) -tcsh (#644402) -zsh (#644400) Partially fixed: Resolved/fixed: -php5 (>= 5.3.1-3) +bash 4.2-1 #641350 +dmidecode 2.11-5 +php5 5.3.1-3 +python2.7 2.7.2-10 +tcsh 6.18.01-1 #644402 +zsh .3.16-1 #644400