Martin Zobel-Helas | 11 Dec 09:05
Picon
Gravatar

[VUA 38-1] Updated tzdata package


---------------------------------------------------------------------------
Debian Volatile Update Announcement VUA 38-1     http://volatile.debian.org
debian-volatile <at> lists.debian.org                         Martin Zobel-Helas
December 11, 2007
---------------------------------------------------------------------------

Package              : tzdata
Version              : 2007j-1etch1
Importance           : low
CVE IDs              : -

The tzdata package in etch does not contain up-to-date timezone
information for:

  * America/Indiana/Vincennes
  * Antarctica/McMurdo
  * Australia
  * Brazil
  * Cuba
  * Egypt
  * Iran
  * Palestine
  * Venezuela

Additional the following timezones have been added:

  * America/Marigot
  * America/St. Barthelemy

(Continue reading)

Martin Zobel-Helas | 11 Dec 10:33
Picon
Favicon

[VUA 39-1] Updated postgrey packages updates whitelist


---------------------------------------------------------------------------
Debian Volatile Update Announcement VUA 39-1     http://volatile.debian.org
debian-volatile <at> lists.debian.org                         Martin Zobel-Helas
December 11, 2007
---------------------------------------------------------------------------

Package              : postgrey
Version              : 1.27-4volatile1
Importance           : low
CVE IDs              : -

The whitelist of postgrey, a postfix greylisting policy server,
has been updated.

For etch, an updated postgrey package is available in etch/volatile as
version 1.27-4volatile1. A newer version for sarge will follow the next
days as follow up to this VUA.

Upgrade Instructions
--------------------

You can get the updated packages at

http://volatile.debian.org/debian-volatile/pool/volatile/main/p/postgrey

and install them with dpkg, or add 

 deb http://volatile.debian.org/debian-volatile etch/volatile main
 deb-src http://volatile.debian.org/debian-volatile etch/volatile main
(Continue reading)

Martin Zobel-Helas | 17 Dec 08:00
Picon
Favicon

[VUA 39-2] Updated postgrey packages update whitelist


---------------------------------------------------------------------------
Debian Volatile Update Announcement VUA 39-2     http://volatile.debian.org
debian-volatile <at> lists.debian.org                         Martin Zobel-Helas
December 17, 2007
---------------------------------------------------------------------------

Package              : postgrey
Version              : 1.27-4volatile1 and 1.21-1volatile5
Importance           : low
CVE IDs              : -

The whitelist of postgrey, a postfix greylisting policy server, has been
updated. This update only adds the package for sarge.

For etch, an updated postgrey package is available in etch/volatile as
version 1.27-4volatile1. 

For sarge, an updated postgrey package is available in sarge/volatile as
version 1.21-1volatile5.

Upgrade Instructions
--------------------

You can get the updated packages at

http://volatile.debian.org/debian-volatile/pool/volatile/main/p/postgrey

and install them with dpkg, or add 

(Continue reading)

Andreas Barth | 20 Dec 21:17

[VUA 40-1] Updated clamav package fixes security flaw

---------------------------------------------------------------------------
Debian Volatile Update Announcement VUA 40-1     http://volatile.debian.org
debian-volatile <at> lists.debian.org                              Andreas Barth
December 20th, 2007
---------------------------------------------------------------------------

Package              : clamav
Version              : sarge: 0.92~dfsg-0volatile2; etch: 0.92~dfsg-1~volatile2
Importance           : high
CVE IDs              : CVE-2007-6335, CVE-2007-6336, CVE-2007-6337

The following securitys flaw were found and fixed in clamav:

 [CVE-2007-6335] MEW PE File Integer Overflow, remote code execution.
 [CVE-2007-6336] Off-by-one error in LZX_READ_HUFFSYM(), remote code execution.
 [CVE-2007-6337] bzlib issue,

For sarge, an updated ClamAV package is available in sarge/volatile as
version 0.92~dfsg-0volatile2.

For etch, an updated ClamAV package is available in etch/volatile as
version 0.92~dfsg-1~volatile2.

Upgrade Instructions
--------------------

You can get the updated packages at

http://volatile.debian.org/debian-volatile/pool/volatile/main/c/clamav

(Continue reading)

Picon
Favicon

[VUA 41-1] Updated tzdata package


---------------------------------------------------------------------------
Debian Volatile Update Announcement VUA 41-1     http://volatile.debian.org
debian-volatile <at> lists.debian.org                 Felipe Augusto van de Wiel
December 28th, 2007 				    and Margarita Manterola
---------------------------------------------------------------------------

Package              : tzdata
Version              : 2007j-1etch2
Importance           : low
CVE IDs              : -

The tzdata package in etch does not contain up-to-date timezone
information for Argentina, due to the sudden decision on changing
the daylight saving time.

For etch, an updated tzdata package is available in etch/volatile
as version 2007j-1etch2.

We recommend that you update your system.

Upgrade Instructions
--------------------

You can get the updated packages at

http://volatile.debian.org/debian-volatile/pool/volatile/main/t/tzdata

and install them with dpkg, or add

(Continue reading)


Gmane