Secure testing team - Mar 2006

Friday March 31 2006
TimeRepliesSubject
5:07AM 0 CAN-2006-1059 [jerry@samba.org: [SECURITY] Samba 3.0.21-3.0.21c: Exposure of machine account credentials in winbindd log files]
 
Wednesday March 29 2006
TimeRepliesSubject
8:28PM 1 horde problem.
3:26PM 9 horde problem.
 
Tuesday March 14 2006
TimeRepliesSubject
3:29PM 0 Re: cURL Buffer Overflow
 
Monday March 13 2006
TimeRepliesSubject
12:28PM 9 Tracker implementation support
12:28PM 1 Re: <package> Buffer Overflow
12:28PM 6 Assigning unique identifiers (CVE?)
12:28PM 1 Re: Freeciv DoS vulnerability
12:28PM 1 Meeting reminder
12:28PM 0 Kone solange
12:28PM 0 Kone solange
12:28PM 1 A first shot at flow modeling
12:28PM 2 security endeavours
12:28PM 5 Meeting Tuesday
12:28PM 0 security testing Howto
12:28PM 0 Kone solange
12:28PM 0 Kone solange
12:28PM 0 Kone solange
12:28PM 10 Re: Bug#342943: only kronolith2 fixed
12:28PM 6 debsecan announcement
12:28PM 0 Kone solange
12:28PM 0 Kone solange
12:28PM 0 Question from eBay Member : coonie2c
12:28PM 0 A/C Sr. Diretor de Marketing
12:28PM 0 一時間以内に女性お届けします!
12:28PM 0 Kone solange
12:28PM 1 Bringing the tracker into shape for Woody and Sarge
12:28PM 0 HP, IBI, BtoB, Oracle, Sap, IBM customer lists
12:28PM 0 phpBB 2.0.19 released, Debian appears not vulnerable
12:28PM 4 ongoing security discussions
12:28PM 4 Introducing <no-dsa>
12:28PM 10 Re: flyspray: Multiple XSS vulnerabilities
12:28PM 2 Stable Kernel issues
12:28PM 0 Work on TODOs
12:28PM 1 CVE status
12:28PM 2 phpbb, CVE-2005-3799: not vulnerable
12:28PM 1 New clamav vulnerabilities
12:28PM 0 Security issue with friendsd from gpsdrive
12:28PM 0 Narrative of testing security tracking
12:28PM 2 secure-testing-commits broken
12:28PM 7 Debian Security Analyzer (debsecan)
12:28PM 17 kernel allows loadkeys to be used by any user, allowing for local root compromise
12:28PM 3 [linux-2.6] Fix signedness issues in net/core/filter.c
12:28PM 5 CVE-2005-2973: Yet another kernel DoS
12:28PM 0 bts usertags for CVE ids
12:28PM 0 NVD cross-references
12:28PM 3 Re: iDEFENSE Security Advisory [IDEF1202] Multiple Vendor wget/curl NTLM Buffer Overflow Vulnerability
12:28PM 1 Adding signatures to the public key of the archive
12:28PM 10 Re: Bug#335938: mantis: Mantis ''t_core_path'' File Inclusion Vulnerability
12:28PM 0 Re: Bug#332259: spampd fails with ''Error in process_request'': Modification of read-only variable in Syslog.pm
12:28PM 5 Re: Bug#332259: spampd fails with ''Error in process_request'': Modification of read-only variable in Syslog.pm
12:28PM 0 [sethg@GoodmanAssociates.com: repository information for DTSA''s]
12:28PM 1 Usertags in the BTS
12:28PM 1 Something is wrong with the mirroring
12:28PM 7 Another syntax addition: <removed>
12:28PM 1 Another kernel vulnerability
12:28PM 3 2.6.13.{123}
12:28PM 2 A new round of kernel vulnerabilities
12:28PM 0 CAN-2005-2933: Arbitrary code execution in uw-imap
12:28PM 0 Re: [mkanat@bugzilla.org: Security Advisory for Bugzilla 2.18.3, 2.20rc2, and 2.21]
12:28PM 8 Three more security problems in the 2.6 kernel
12:28PM 2 testing security status
12:28PM 3 Proposed syntax changes for CAN/list / finalization phase
12:28PM 0 libpam-ldap DSA-785 fixed CAN-2005-2069 w/o mentioning it
12:28PM 2 Oldenburg 2nd meeting summary
12:28PM 0 Oldenburg 1st meeting summary
12:28PM 2 stable security versions
12:28PM 1 Keeping us busy in Oldenburg
12:28PM 1 2.6.13.2
12:28PM 7 "FIXES:" and "FIXED-BY:" directives
12:28PM 0 RealPlayer is typically *not* not-for-us
12:28PM 0 Re: Bug#328395: CAN-2005-2801: ext2 ext3 xattr access control bypass
12:28PM 1 Re: announcing the beginning of security support for testing
12:28PM 0 Two more kernel related DoS vulnerabilities
12:28PM 2 [bug??] apt pinning on testing/etch secuirty archive
12:28PM 0 mod-auth-shadow bug 323789
12:28PM 16 [patch 0/3] Syntax tweaks for data/CAN/list
12:28PM 6 kernel update
12:28PM 14 summary of what''s blocking security fixes from testing
12:28PM 3 Long, long, long tag
12:28PM 4 Proposal: new tags
12:28PM 0 Repository does not work with APT::Default-Release "testing"
12:28PM 1 DSA-315 / gnocatan
12:28PM 3 Re: summary of what''s blocking security fixes
12:28PM 0 Re: announcing the beginning of security support for testing
12:28PM 1 Mirroring debian-secure-testing
12:28PM 3 CAN and CVE directories
12:28PM 2 Recording fixed versions in sarge
12:28PM 1 Re: announcing the beginning of security support for testing
12:28PM 3 Let''s remove entries for issues that only manifest in the source package
12:28PM 2 Re: announcing the beginning of security support for testing
12:28PM 7 what else needs a DTSA right now?
12:28PM 1 Guidelines for testing security fixes
12:28PM 3 2.6.12.6
12:28PM 9 DTSA for 2.6.8 and 2.4.27
12:28PM 0 Matthias Urlichs: Urlaub/Vacation
12:28PM 0 Introducing not-affected
12:28PM 12 simpleproxy upload gone AWOL?
12:28PM 0 Re: secure-testing details
12:28PM 11 DTSA advisory format
12:28PM 4 update on issuing advisories
12:28PM 9 simpleproxy with fix, etch built
12:28PM 0 (forw) Re: secure-testing details
12:28PM 0 test package needed for new repo
12:28PM 19 Moving forward with the 2.4.27 and 2.6.8 kernels
12:28PM 8 status of first round of sarge kernel updates
12:28PM 0 Let''s track information about embedded sources in packages
12:28PM 1 Recent gforge vulnerabilities affect Debian''s 3.1 as well?
12:28PM 0 Re: Bug#322237: kernel-image-2.6.8-11-amd64-k8-smp: [PATCH] Panic on ipt_recent - 32bitism
12:28PM 0 Re: Bug#319016: Information leak through insufficient permissions on backup files in kate (CAN-2005-1920)
12:28PM 1 ekg: Bug#318970 - possibly remotely exploitable integer overflow
12:28PM 0 tracking page
12:28PM 9 ekg: CAN-2005-1916 Bug#317027 and #318059
12:28PM 0 Repository setup
12:28PM 2 Re: Addressing the recent zlib issue
12:28PM 3 Re: Bug#309308: kernel-image-2.6.8-2-686-smp: VLAN Oops fix for 2.6.8
12:28PM 4 Re: Bug#322273: [CAN-2005-2456]: XFRM array index buffer overflow
12:28PM 0 Re: ACL patches in Debian 2.4 series kernel.
12:28PM 6 A full audit of SPARC arch by our static binary analysis tool
12:28PM 1 One more sec issue
12:28PM 1 question regarding procedures
12:28PM 1 another question: backport fixes?
12:28PM 1 tracking page for stable
12:28PM 0 proftpd bug of interest for sarge
12:28PM 0 Idea for GAIM add-on (maybe a Summer of Code Project)
12:28PM 0 Idea for GAIM add-on (maybe a Summer of Code Project)
12:28PM 0 DTSA processing WIP code
12:28PM 0 Some severity readjustments
12:28PM 5 Broken testing propagation for some packages?
12:28PM 1 Anyone speaking Russian among you?
12:28PM 0 xmlrpc mess
12:28PM 4 Security updates for Etch?
12:28PM 0 Re: ettercap - CAN-2005-1796
12:28PM 1 Tagging gaim bug ''security''
12:28PM 0 Yet another security update for ''elog''
12:28PM 0 elogs
12:28PM 1 ELF problems
12:28PM 0 little survey
12:28PM 7 Integer overflow in applications parsing ELF headers
12:28PM 1 Re: Accepted elog 2.5.7+r1558-2 (i386 source)
12:28PM 2 svn.d.o <-> Alioth broken?
12:28PM 45 Security update for fuse
12:28PM 1 regarding elog
12:28PM 2 ettercap: [CAN-2005-1796] buffer overflow in ec_curses.c
12:28PM 2 evolution security bug needs help
12:28PM 2 talk at DebConf5
12:28PM 1 Status page broken
12:28PM 15 Kernel vulnerabilities in sarge-checks
12:28PM 13 Re: xpdf vulnerability?
12:28PM 0 Re: xpdf vulnerability? (was: Bits from the Testing Security team)
12:28PM 0 Re: xpdf vulnerability?
12:28PM 0 Re: xpdf vulnerability?
12:28PM 0 the empty list
12:28PM 5 Status of unfixed security issues
12:28PM 1 Re: Bug#301430: Multiple exploitable race conditions in openmosixview
12:28PM 5 status of getting security fixes into sarge
12:28PM 3 page with unfixed holes
12:28PM 0 automatic CAN updates
12:28PM 1 bug in testing status page?
12:28PM 1 "testing security issues" - PuTTY
12:28PM 0 About uim security bug (CAN-2005-0503)
12:28PM 0 Testing security webpage
12:28PM 0 our work is making an impact
12:28PM 1 testing-security.html empty
12:28PM 0 "Improving Security in Debian" Paper for Debconf5
12:28PM 11 resolving hard TODOs
12:28PM 0 Linux Kernel SMBFS Multiple Remote Vulnerabilities
12:28PM 5 report on current state of sarge security
12:28PM 3 done with the woody CANs
12:28PM 0 new list, update
12:28PM 0 new list, update
 
Friday March 10 2006
TimeRepliesSubject
8:36PM 1 r3588 - data/CVE