<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Gentoo | Security</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/gentoo/security/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>13 Feb  2012 03:52:14 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Gentoo | Security</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/gentoo/security/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>[no subject]</title>
<description></description>
<pubDate>08 Dec  2011 22:21:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/244096</link>
</item><item>
<title>Re: CVE-2011-4313 - BIND 9 Resolver crashes after logging an error in query.c</title>
<description>On Nov 17, 2011, at 1:30 AM, David Sommerseth wrote: &amp;gt; &amp;gt; Hi, &amp;gt; &amp;gt; This is a very fresh CVE, and I wondered if this has caught your attention? &amp;gt; When</description>
<pubDate>17 Nov  2011 00:48:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/242696</link>
</item><item>
<title>CVE-2011-4313 - BIND 9 Resolver crashes after logging an error in query.c</title>
<description>Hi, This is a very fresh CVE, and I wondered if this has caught your attention? When would it be reasonable to expect an update for this issue? ISC</description>
<pubDate>16 Nov  2011 23:30:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/242692</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>Rich Freeman wrote, on 08/27/2011 03:06 PM: &amp;gt; However, that isn&amp;#039;t really what we&amp;#039;re discussing here. What we&amp;#039;re &amp;gt; talking about is GLSAs vs no GLSAs.</description>
<pubDate>27 Aug  2011 06:34:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237182</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>On Sat, Aug 27, 2011 at 8:34 AM, Tobias Heinlein &amp;lt;keytoaster@gentoo.org&amp;gt; wrote: &amp;gt; I have read that idea multiple times now, each of them by people not</description>
<pubDate>27 Aug  2011 06:06:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237181</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>Rich Freeman wrote, on 08/27/2011 02:13 PM: &amp;gt; Note that I&amp;#039;m basically advocating ditching the tool. A tool is good &amp;gt; when it improves productivity.</description>
<pubDate>27 Aug  2011 05:34:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237180</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>On Sat, Aug 27, 2011 at 4:49 AM, Christian Kauhaus &amp;lt;kc@gocept.com&amp;gt; wrote: &amp;gt; So in consequence I would appreciate to have both mechanisms: a timely &amp;gt; u</description>
<pubDate>27 Aug  2011 05:13:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237179</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>Am 26.08.2011 20:08, schrieb Kevin Bryan: &amp;gt; SECURITY_FIXES=&amp;quot;&amp;lt;www-plugins/adobe-flash-10.1.102.64&amp;quot; &amp;gt; SECURITY_REF=&amp;quot;CVE:2010-2169 http://...&amp;quot; &amp;gt; SECURITY</description>
<pubDate>27 Aug  2011 01:49:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237175</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>But Alex, this could be a great improvement in system at all. This can help administrators to measure better its systems, and may be &amp;quot;force&amp;quot; developer</description>
<pubDate>26 Aug  2011 16:38:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237171</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>On Friday 26 August 2011 16:02:56 Kevin Bryan wrote: &amp;gt; I was not considering the entire process, just the part that really &amp;gt; impacts me: identifying v</description>
<pubDate>26 Aug  2011 15:27:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237168</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>I like this approach but I have no idea about how this could be performed. ACCEPT_RISKS=&amp;quot;remote dos&amp;quot; emerge ... Sounds very cool to me. Daniel On</description>
<pubDate>26 Aug  2011 13:40:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237163</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I was not considering the entire process, just the part that really impacts me: identifying vulnerable</description>
<pubDate>26 Aug  2011 13:02:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237162</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>On Friday, August 26, 2011 08:07:57 PM Alex Legler wrote: &amp;gt; On Friday 26 August 2011 20:00:15 Joost Roeleveld wrote: &amp;gt; &amp;gt; On Friday, August 26, 2011 07</description>
<pubDate>26 Aug  2011 12:30:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237161</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>Alex. For WEB vulnerability discovering, one of the most important to us is Nessus to search and confronting against CVE database. Sometimes, Nessus</description>
<pubDate>26 Aug  2011 12:27:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237160</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>On Friday 26 August 2011 15:22:40 Daniel A. Avelino wrote: &amp;gt; &amp;gt; When I think about automation, I had in mind something that could help &amp;gt; &amp;gt; developers</description>
<pubDate>26 Aug  2011 11:44:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237159</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>Hi Kevin. That is an interesting idea. So one could check about vulnerabilies solutions _before_ package installation. And better. This could give us</description>
<pubDate>26 Aug  2011 11:41:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237155</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>On Friday 26 August 2011 14:08:38 Kevin Bryan wrote: &amp;gt; Although I like having the summary information about what the &amp;gt; vulnerability is, if I&amp;#039;m only r</description>
<pubDate>26 Aug  2011 11:40:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237154</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>On Fri, Aug 26, 2011 at 2:57 PM, Alex Legler &amp;lt;a3li@gentoo.org&amp;gt; wrote: &amp;gt; On Friday 26 August 2011 14:18:20 Daniel A. Avelino wrote: &amp;gt; &amp;gt; Alex. &amp;gt; &amp;gt; &amp;gt; &amp;gt;</description>
<pubDate>26 Aug  2011 11:22:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237153</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Although I like having the summary information about what the vulnerability is, if I&amp;#039;m only reading the</description>
<pubDate>26 Aug  2011 11:08:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237152</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>On Friday 26 August 2011 20:00:15 Joost Roeleveld wrote: &amp;gt; On Friday, August 26, 2011 07:06:35 PM Christian Kauhaus wrote: &amp;gt; &amp;gt; Am 26.08.2011 18:55, sc</description>
<pubDate>26 Aug  2011 11:07:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237151</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>On Friday 26 August 2011 14:18:20 Daniel A. Avelino wrote: &amp;gt; Alex. &amp;gt; &amp;gt; May be a call for volunteers more &amp;quot;intense&amp;quot; could improve the manpower. This &amp;gt;</description>
<pubDate>26 Aug  2011 10:57:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237150</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>Alex. May be a call for volunteers more &amp;quot;intense&amp;quot; could improve the manpower. This could be a more easy start point to address, no?. I work too in so</description>
<pubDate>26 Aug  2011 10:18:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237149</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>Am 26.08.2011 18:55, schrieb Alex Legler: &amp;gt; Compared to other distributions, our advisories have been rather detailed with &amp;gt; lots of manually research</description>
<pubDate>26 Aug  2011 10:06:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237148</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>On Friday 26 August 2011 18:12:00 Christian Kauhaus wrote: &amp;gt; Hi, &amp;gt; &amp;gt; I&amp;#039;m wondering that may favorite Linux distro hasn&amp;#039;t had any security &amp;gt; announcem</description>
<pubDate>26 Aug  2011 09:55:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237145</link>
</item><item>
<title>Re: No GLSA since January?!?</title>
<description>Dear Christian Everything is secure. No reason to write GLSAs or to panic. ;)  Chris Am 26.08.2011 um 18:12 schrieb Christian Kauhaus: &amp;gt; Hi, &amp;gt; &amp;gt;</description>
<pubDate>26 Aug  2011 09:43:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237144</link>
</item><item>
<title>No GLSA since January?!?</title>
<description>Hi, I&amp;#039;m wondering that may favorite Linux distro hasn&amp;#039;t had any security announcements since January. In my opinion this is really problematic. At o</description>
<pubDate>26 Aug  2011 09:12:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/237143</link>
</item><item>
<title>Ruxcon 2011 Final Call For Papers</title>
<description>Ruxcon 2011 Final Call For Papers The Ruxcon team is pleased to announce the final call for papers for the seventh annual Ruxcon conference. This ye</description>
<pubDate>15 Aug  2011 03:53:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/236342</link>
</item><item>
<title>Re: Invitation to connect on LinkedIn</title>
<description>Shit happens - sorry to all of you guys. Linkedin did do it somehow and i didnt notice. Too much coffee and not enough sleep. Sorry ;) Regards 11-08-</description>
<pubDate>11 Aug  2011 01:09:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/236172</link>
</item><item>
<title>Re: Invitation to connect on LinkedIn</title>
<description>Benefit of doubt linkedin crawls your contact list and sends out invites to all? On Aug 10, 2011 5:21 PM, &amp;quot;Bernhard Egger&amp;quot; &amp;lt;bernhard@aces.snu.ac.kr&amp;gt; w</description>
<pubDate>10 Aug  2011 20:29:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/236143</link>
</item><item>
<title>Re: Invitation to connect on LinkedIn</title>
<description>I think more likely it was that linkdin was given access to his email address book... But hey you also sent yr reply to the list... On Aug 10, 2011,</description>
<pubDate>10 Aug  2011 20:02:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/236142</link>
</item><item>
<title>Re: Invitation to connect on LinkedIn</title>
<description>Dude? 1. Do i know you? 2. Send what to a list?  On Wed, Aug 10, 2011 at 5:15 PM, Bernhard Egger &amp;lt;bernhard@aces.snu.ac.kr&amp;gt;wrote: &amp;gt; dude, you send</description>
<pubDate>10 Aug  2011 17:29:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/236133</link>
</item><item>
<title>Re: Invitation to connect on LinkedIn</title>
<description>dude, you send this to a list?! On 08/10/2011 07:10 AM, Wojciech Ziniewicz wrote: &amp;gt; &amp;gt;  LinkedIn &amp;gt; &amp;gt; I&amp;#039;d like to add you to my professional network</description>
<pubDate>10 Aug  2011 17:15:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/236132</link>
</item><item>
<title>Invitation to connect on LinkedIn</title>
<description>LinkedIn ------------    I&amp;#039;d like to add you to my professional network on LinkedIn. - Wojciech Wojciech Ziniewicz Lead System Engineer at 314 T</description>
<pubDate>09 Aug  2011 15:10:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/236076</link>
</item><item>
<title>Ruxcon 2011 Call For Papers</title>
<description>Ruxcon 2011 Call For Papers The Ruxcon team is pleased to announce the call for papers for the seventh annual Ruxcon conference. This year the confe</description>
<pubDate>16 May  2011 23:37:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/230769</link>
</item><item>
<title>[no subject]</title>
<description>-- Corpex Internet GmbH * Schauenburgerstraße 6 * D-20095 Hamburg Tel: +49 40 822268-0 * Fax: +49 40 822268-100 * http://www.corpex.de/ HRB 78752, Am</description>
<pubDate>05 Jan  2011 02:40:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/223859</link>
</item><item>
<title>Re: #342619 RESOLVED WONTFIX</title>
<description>2010/10/28 Mateusz Arkadiusz Mierzwinski &amp;lt;mateuszmierzwinski@gmail.com&amp;gt; &amp;gt; 2010/10/28 Pavel Labushev &amp;lt;p.labushev@gmail.com&amp;gt; &amp;gt; &amp;gt; &amp;gt; I didn&amp;#039;t test that p</description>
<pubDate>28 Oct  2010 04:05:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/220203</link>
</item><item>
<title>Re: #342619 RESOLVED WONTFIX</title>
<description>2010/10/28 Pavel Labushev &amp;lt;p.labushev@gmail.com&amp;gt; &amp;gt; &amp;gt; I didn&amp;#039;t test that patch; even if it&amp;#039;s incorrect, bugreport is not about &amp;gt; &amp;gt; a patch. It&amp;#039;s about</description>
<pubDate>28 Oct  2010 02:50:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/220189</link>
</item><item>
<title>Re: #342619 RESOLVED WONTFIX</title>
<description>&amp;gt; I didn&amp;#039;t test that patch; even if it&amp;#039;s incorrect, bugreport is not about &amp;gt; a patch. It&amp;#039;s about a security issue. Well, the bug report is about the</description>
<pubDate>27 Oct  2010 18:23:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/220164</link>
</item><item>
<title>Re: #342619 RESOLVED WONTFIX</title>
<description>&amp;gt; eruption or something else. Now collection is expanded to patches that &amp;gt; will not be mainstreamed :&amp;gt; This is GOOD PRACTICE :). Thinking about Anoth</description>
<pubDate>27 Oct  2010 18:14:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/220163</link>
</item><item>
<title>Re: #342619 RESOLVED WONTFIX</title>
<description>On Wed, Oct 27, 2010 at 08:33:56PM +0200, Volker Armin Hemmann wrote: &amp;gt; please show me some enterprise distros incorporating that patch. I didn&amp;#039;t tes</description>
<pubDate>27 Oct  2010 17:23:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/220157</link>
</item><item>
<title>Re: #342619 RESOLVED WONTFIX</title>
<description>2010/10/27 Volker Armin Hemmann &amp;lt;volkerarmin@googlemail.com&amp;gt; &amp;gt; On Wednesday 27 October 2010, Kirktis wrote: &amp;gt; &amp;gt; and people wonder why gentoo is not t</description>
<pubDate>27 Oct  2010 12:32:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/220146</link>
</item><item>
<title>Re: #342619 RESOLVED WONTFIX</title>
<description>On Wednesday 27 October 2010, Kirktis wrote: &amp;gt; and people wonder why gentoo is not taken seriously by the enterprise. &amp;gt; &amp;gt; On 10/27/10, dev-random@mai</description>
<pubDate>27 Oct  2010 11:33:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/220142</link>
</item><item>
<title>Re: #342619 RESOLVED WONTFIX</title>
<description>and people wonder why gentoo is not taken seriously by the enterprise. On 10/27/10, dev-random@mail.ru &amp;lt;dev-random@mail.ru&amp;gt; wrote: &amp;gt; #342619 [[url]ht</description>
<pubDate>26 Oct  2010 22:52:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/220120</link>
</item><item>
<title>#342619 RESOLVED WONTFIX</title>
<description>#342619 [[url]http://bugs.gentoo.org/342619] RESOLVED WONTFIX Are you intentionally leaving security hole in system?</description>
<pubDate>26 Oct  2010 12:15:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/220111</link>
</item><item>
<title>Re: Re: Kernel Security Update Target Delay?</title>
<description>On Sun, 2010-10-17 at 19:58 +0100, Graham Murray wrote: &amp;gt; Alex Legler &amp;lt;a3li@gentoo.org&amp;gt; writes: &amp;gt; &amp;gt; &amp;gt; As the maintainers are primarily responsible fo</description>
<pubDate>17 Oct  2010 12:46:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/219734</link>
</item><item>
<title>Re: Re: Kernel Security Update Target Delay?</title>
<description>Alex Legler &amp;lt;a3li@gentoo.org&amp;gt; writes: &amp;gt; As the maintainers are primarily responsible for providing unaffected &amp;gt; ebuilds, you&amp;#039;ll need to ask the kerne</description>
<pubDate>17 Oct  2010 11:58:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/219733</link>
</item><item>
<title>Re: Re: Kernel Security Update Target Delay?</title>
<description>On 10/17/2010 04:51 PM, Alex Legler wrote: &amp;gt; Er, who here assessed the issue to be not &amp;quot;important&amp;quot;? &amp;gt;&amp;gt; [...] &amp;gt; You seem to be assuming that we (=Gento</description>
<pubDate>17 Oct  2010 11:00:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/219732</link>
</item><item>
<title>Re: Re: Kernel Security Update Target Delay?</title>
<description>On 10/17/2010 11:51 AM, Alex Legler wrote: &amp;gt; Excerpts from Israel G. Lugo&amp;#039;s message of Sun Oct 17 15:59:15 +0200 2010: &amp;gt;&amp;gt; Your own &amp;gt;&amp;gt; vulnerability tr</description>
<pubDate>17 Oct  2010 09:43:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/219728</link>
</item><item>
<title>Re: Re: Kernel Security Update Target Delay?</title>
<description>I just wanted to clarify that my intent is not to complain, or to imply that Gentoo devs aren&amp;#039;t working hard enough, or that &amp;quot;Gentoo sucks&amp;quot; or anythin</description>
<pubDate>17 Oct  2010 08:54:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/219727</link>
</item><item>
<title>Re: Re: Kernel Security Update Target Delay?</title>
<description>Excerpts from Israel G. Lugo&amp;#039;s message of Sun Oct 17 15:59:15 +0200 2010: &amp;gt; So what&amp;#039;s the conclusion on what happened with bug 337645? What can we &amp;gt; l</description>
<pubDate>17 Oct  2010 08:51:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/219726</link>
</item><item>
<title>Re: Kernel Security Update Target Delay?</title>
<description>Greetings, So what&amp;#039;s the conclusion on what happened with bug 337645? What can we learn from here? That everything went just fine and according to pl</description>
<pubDate>17 Oct  2010 06:59:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/219724</link>
</item><item>
<title>Re: Kernel Security Update Target Delay?</title>
<description>Excerpts from Richard Freeman&amp;#039;s message of Sun Sep 26 20:17:24 +0200 2010: &amp;gt; On 09/26/2010 12:56 PM, Robin H. Johnson wrote: &amp;gt; &amp;gt; Even hardened-kernel</description>
<pubDate>26 Sep  2010 15:10:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/218776</link>
</item><item>
<title>Re: Kernel Security Update Target Delay?</title>
<description>Excerpts from Calum&amp;#039;s message of Sun Sep 26 19:28:01 +0200 2010: &amp;gt; On 26 September 2010 11:31, Richard Freeman &amp;lt;rich0@gentoo.org&amp;gt; wrote: &amp;gt; &amp;gt; Gentoo ha</description>
<pubDate>26 Sep  2010 14:42:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/218775</link>
</item><item>
<title>Re: Kernel Security Update Target Delay?</title>
<description>On 09/26/2010 12:56 PM, Robin H. Johnson wrote: &amp;gt; Even hardened-kernel was fixed within 2 days of bug opening. &amp;gt; &amp;gt; The delay is in stabilization, and</description>
<pubDate>26 Sep  2010 11:17:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/218763</link>
</item><item>
<title>Re: Kernel Security Update Target Delay?</title>
<description>On 26 September 2010 11:31, Richard Freeman &amp;lt;rich0@gentoo.org&amp;gt; wrote: &amp;gt; Gentoo has been vulnerable to a highly-publicized (Guardian, Slashdot, &amp;gt; the w</description>
<pubDate>26 Sep  2010 10:28:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/218762</link>
</item><item>
<title>Re: Kernel Security Update Target Delay?</title>
<description>On Sun, Sep 26, 2010 at 08:16:22AM -0400, Richard Freeman wrote: &amp;gt; On 09/26/2010 07:51 AM, Volker Armin Hemmann wrote: &amp;gt; &amp;gt; so there has been roughly a</description>
<pubDate>26 Sep  2010 09:56:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/218758</link>
</item><item>
<title>Re: Kernel Security Update Target Delay?</title>
<description>On 09/26/2010 07:51 AM, Volker Armin Hemmann wrote: &amp;gt; so there has been roughly a week so far. Agreed - 10 days was the figure I mentioned. So far w</description>
<pubDate>26 Sep  2010 05:16:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/218746</link>
</item><item>
<title>Re: Kernel Security Update Target Delay?</title>
<description>On Sunday 26 September 2010, Richard Freeman wrote: *gentoo-sources-2.6.32-r18 (21 Sep 2010)  21 Sep 2010; Mike Pagano &amp;lt;mpagano@gentoo.org&amp;gt;  +gento</description>
<pubDate>26 Sep  2010 04:51:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/218745</link>
</item><item>
<title>Kernel Security Update Target Delay?</title>
<description>Gentoo has been vulnerable to a highly-publicized (Guardian, Slashdot, the works) local privilege escalation for almost two weeks now. (Well, it has</description>
<pubDate>26 Sep  2010 03:31:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/218741</link>
</item><item>
<title>Re: Security team meeting - Summary</title>
<description>Security Project Meeting 2010-09-01 =================================== Roll call ---------  here:   Alex Legler (a3li)   Tony Vroon (chainsaw),</description>
<pubDate>09 Sep  2010 13:35:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/217874</link>
</item><item>
<title>Re: Security team meeting - September 1 at 18:30 UTC (20:30 CEST)</title>
<description>Matthias Geerdsen &amp;lt;vorlon@gentoo.org&amp;gt; said: &amp;gt; Hi everyone, &amp;gt; &amp;gt; the security project will hold a public meeting in #gentoo-security on &amp;gt; freenode this</description>
<pubDate>30 Aug  2010 17:05:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/217372</link>
</item><item>
<title>Security team meeting - September 1 at 18:30 UTC (20:30 CEST)</title>
<description>Hi everyone, the security project will hold a public meeting in #gentoo-security on freenode this wednesday, 2010-09-01 at 18:30 UTC (20:30 CEST). T</description>
<pubDate>30 Aug  2010 13:10:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/217361</link>
</item><item>
<title>Ruxcon 2010 Final Call For Papers</title>
<description>RUXCON 2010 FINAL CALL FOR PAPERS Ruxcon would like to announce the final call for papers for the sixth annual Ruxcon conference. This year the conf</description>
<pubDate>19 Aug  2010 19:13:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/216775</link>
</item><item>
<title>RE: portage/rsync question</title>
<description>So to avoid &amp;quot;spamming&amp;quot; with 20+ Thank You emails I&amp;#039;ll send out just one and thank you all collectively for the information provided (I hope this isn&amp;#039;t</description>
<pubDate>07 Apr  2010 08:06:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/210470</link>
</item><item>
<title>Re: portage/rsync question</title>
<description>On Tue, Apr 6, 2010 at 2:56 PM, Butterworth, John W. &amp;lt;jbutterworth@mitre.org&amp;gt; wrote: &amp;gt; If someone makes a change to a copy of a program (say a backdoo</description>
<pubDate>06 Apr  2010 19:14:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/210441</link>
</item><item>
<title>Re: portage/rsync question</title>
<description>07.04.2010 04:20, Volker Armin Hemmann Ð¿Ð¸ÑˆÐµÑ‚: &amp;gt; If he changes the ebuild - well... emerge-webrsync with webrsync-gpg FEATURE could be used to m</description>
<pubDate>06 Apr  2010 14:15:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/210434</link>
</item><item>
<title>Re: portage/rsync question</title>
<description>On Tue, Apr 6, 2010 at 11:45 PM, Butterworth, John W. &amp;lt; jbutterworth@mitre.org&amp;gt; wrote: &amp;gt; Thank you Shimi. &amp;gt; &amp;gt; I also came across a couple threads in</description>
<pubDate>06 Apr  2010 14:06:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/210433</link>
</item><item>
<title>RE: portage/rsync question</title>
<description>Thank you Shimi.  I also came across a couple threads in my research: http://sources.gentoo.org/viewcvs.py/gentoo/users/robbat2/tree-signing-gleps/</description>
<pubDate>06 Apr  2010 13:45:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/210425</link>
</item><item>
<title>Re: portage/rsync question</title>
<description>On Tue, Apr 6, 2010 at 10:26 PM, Butterworth, John W. &amp;lt; jbutterworth@mitre.org&amp;gt; wrote: &amp;gt; Hi. I have a security-related question for Portage/rsync:</description>
<pubDate>06 Apr  2010 13:26:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/210424</link>
</item><item>
<title>Re: portage/rsync question</title>
<description>On Dienstag 06 April 2010, Butterworth, John W. wrote: &amp;gt; Hi. I have a security-related question for Portage/rsync: &amp;gt; &amp;gt; &amp;gt; &amp;gt; If someone makes a chan</description>
<pubDate>06 Apr  2010 13:20:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/210423</link>
</item><item>
<title>portage/rsync question</title>
<description>Hi. I have a security-related question for Portage/rsync:   If someone makes a change to a copy of a program (say a backdoor added to apache) host</description>
<pubDate>06 Apr  2010 12:26:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/210422</link>
</item><item>
<title>Re: gmonstart / jvregisterclasses in tons of binaries with commands,malware?</title>
<description>On Wed, 2009-12-16 at 21:06 -0500, whereislibertyandjustice@Safe-mail.net wrote: &amp;gt; In linux binaries, in any linux distro, I&amp;#039;ve discovered the same st</description>
<pubDate>17 Dec  2009 03:14:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/203495</link>
</item><item>
<title>Re: gmonstart / jvregisterclasses in tons of binaries with commands,malware?</title>
<description>On 12/17/09 03:06, whereislibertyandjustice@Safe-mail.net wrote: &amp;gt; In linux binaries, in any linux distro, I&amp;#039;ve discovered the same strings &amp;gt; which I</description>
<pubDate>16 Dec  2009 22:00:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/203474</link>
</item><item>
<title>Re: gmonstart / jvregisterclasses in tons of binaries with commands,malware?</title>
<description>On Wed, Dec 16, 2009 at 09:06:04PM -0500, whereislibertyandjustice@Safe-mail.net wrote: &amp;gt; Google results are vague, some suggest shell backdoors, ever</description>
<pubDate>16 Dec  2009 21:20:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/203473</link>
</item><item>
<title>Re: gmonstart / jvregisterclasses in tons of binaries with commands,malware?</title>
<description>whereislibertyandjustice@safe-mail.net said: &amp;gt; In linux binaries, in any linux distro, I&amp;#039;ve discovered the same strings &amp;gt; which I believe may be due t</description>
<pubDate>16 Dec  2009 20:49:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/203472</link>
</item><item>
<title>gmonstart / jvregisterclasses in tons of binaries with commands,malware?</title>
<description>In linux binaries, in any linux distro, I&amp;#039;ve discovered the same strings which I believe may be due to a virus or trojan. Yet, clamav, rkhunter, chkr</description>
<pubDate>16 Dec  2009 18:06:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/203469</link>
</item><item>
<title>Re: the Gentoo Audit project and dev-util/splint</title>
<description>Hello Mansour, On Wednesday 10 June 2009, Mansour Moufid wrote: &amp;gt; &amp;gt; But keep in mind there is a certain amount of work that comes with &amp;gt; &amp;gt; this. &amp;gt; &amp;gt;</description>
<pubDate>11 Jun  2009 07:13:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/191091</link>
</item><item>
<title>Re: the Gentoo Audit project and dev-util/splint</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Thu, Jun 4, 2009 at 6:58 AM, Robert Buchholz&amp;lt;rbu@gentoo.org&amp;gt; wrote: &amp;gt; However note that the Auditing</description>
<pubDate>10 Jun  2009 13:35:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/191001</link>
</item><item>
<title>Re: the Gentoo Audit project and dev-util/splint</title>
<description>On Thursday 04 June 2009, Mansour Moufid wrote: &amp;gt; Hello list, &amp;gt; &amp;gt; I was wondering if I could get peoples&amp;#039; opinions of dev-util/splint &amp;gt; (the Secure Pr</description>
<pubDate>04 Jun  2009 03:58:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/190450</link>
</item><item>
<title>the Gentoo Audit project and dev-util/splint</title>
<description>Hello list, I was wondering if I could get peoples&amp;#039; opinions of dev-util/splint (the Secure Programming Lint) [1], and specifically in the context of</description>
<pubDate>03 Jun  2009 20:44:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/190443</link>
</item><item>
<title>Re: Security project meeting summary</title>
<description>Peter Volkov wrote: &amp;gt; Ð&#039; Ð¡Ñ€Ð´, 13/05/2009 Ð² 17:50 -0500, Aleksey V Lazar Ð¿Ð¸ÑˆÐµÑ‚: &amp;gt;  &amp;gt;  &amp;gt;&amp;gt; I&amp;#039;m using Portage version 2.1.6.13 right now. I</description>
<pubDate>01 Jun  2009 10:24:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/190243</link>
</item><item>
<title>Re: Security project meeting summary</title>
<description>Ð&#039; Ð¡Ñ€Ð´, 13/05/2009 Ð² 17:50 -0500, Aleksey V Lazar Ð¿Ð¸ÑˆÐµÑ‚:  &amp;gt; I&amp;#039;m using Portage version 2.1.6.13 right now. I know for a fact that &amp;gt; I&amp;#039;ve us</description>
<pubDate>29 May  2009 00:19:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/190089</link>
</item><item>
<title>Re: Security project meeting summary</title>
<description>Robert Buchholz wrote: &amp;gt; On Wednesday 13 May 2009, Aleksey V Lazar wrote: &amp;gt;  &amp;gt;&amp;gt; Robert Buchholz wrote: &amp;gt;&amp;gt;   &amp;gt;&amp;gt;&amp;gt; On Tuesday 29 July 2008, Bill wro</description>
<pubDate>13 May  2009 15:50:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/188791</link>
</item><item>
<title>Re: Security project meeting summary</title>
<description>On Wednesday 13 May 2009, Aleksey V Lazar wrote: &amp;gt; Robert Buchholz wrote: &amp;gt; &amp;gt; On Tuesday 29 July 2008, Bill wrote: &amp;gt; &amp;gt;&amp;gt;&amp;gt; Currently (to the best of my</description>
<pubDate>12 May  2009 15:24:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/188722</link>
</item><item>
<title>Re: Security project meeting summary</title>
<description>Robert Buchholz wrote: &amp;gt; On Tuesday 29 July 2008, Bill wrote: &amp;gt;  &amp;gt;&amp;gt;&amp;gt; Currently (to the best of my understanding) there is no easy way &amp;gt;&amp;gt;&amp;gt; (e.g.: an</description>
<pubDate>12 May  2009 15:18:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/188721</link>
</item><item>
<title>Re: small announcement for the community</title>
<description>On Tuesday 03 March 2009 17:30:24 Douglas J Hunley wrote: &amp;gt; A while back I setup a small cron job to parse the GLSA feed and post it to &amp;gt; Twitter. I&amp;#039;v</description>
<pubDate>06 Mar  2009 10:57:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/183449</link>
</item><item>
<title>Re: small announcement for the community</title>
<description>Am Mittwoch 04 MÃ¤rz 2009 schrieb Aleksey V Lazar: &amp;gt; Douglas J Hunley wrote: &amp;gt; &amp;gt; If you want to, simply follow &amp;gt; &amp;gt; @Gentoo_Security and you&amp;#039;ll get &amp;#039;in</description>
<pubDate>05 Mar  2009 00:33:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/183376</link>
</item><item>
<title>Re: small announcement for the community</title>
<description>Twitter. -- Michael Thompson -original message- Subject: Re: [gentoo-security] small announcement for the community From: Aleksey V Lazar &amp;lt;lazar@mnsu</description>
<pubDate>04 Mar  2009 09:47:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/183356</link>
</item><item>
<title>Re: small announcement for the community</title>
<description>Douglas J Hunley wrote: &amp;gt; If you want to, simply follow &amp;gt; @Gentoo_Security and you&amp;#039;ll get &amp;#039;instant&amp;#039; updates of new GLSAs &amp;gt; &amp;gt;  I&amp;#039;m sorry, what does</description>
<pubDate>04 Mar  2009 09:44:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/183355</link>
</item><item>
<title>small announcement for the community</title>
<description>A while back I setup a small cron job to parse the GLSA feed and post it to Twitter. I&amp;#039;ve been tweaking it and watching it and it seems stable enough</description>
<pubDate>03 Mar  2009 14:30:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/183327</link>
</item><item>
<title>Re: TCP Wrapper Documentation</title>
<description>I can think of three reasons: less clutter, less maintenance, and keeping the machine from wasting time parsing the file on busy systems that may have</description>
<pubDate>14 Jan  2009 13:17:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/179459</link>
</item><item>
<title>Re: TCP Wrapper Documentation</title>
<description>Thank you for all the suggestions, they have been very helpful and I now have my tcp wrappers up and running. Just out of curiosity, why doesn&amp;#039;t the</description>
<pubDate>12 Jan  2009 16:32:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/179307</link>
</item><item>
<title>Re: TCP Wrapper Documentation</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256  Hi there... You can also install the &amp;quot;DenyHosts&amp;quot; package, which will parse your syslog for failed</description>
<pubDate>12 Jan  2009 09:50:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/179268</link>
</item><item>
<title>Re: TCP Wrapper Documentation</title>
<description>Search for &amp;quot;tcp wrappers howto&amp;quot; on Google. Yes, this must be maintained manually. I recommend to do away with /etc/host.deny and have &amp;quot;ALL :ALL@ALL :d</description>
<pubDate>09 Jan  2009 21:51:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/179152</link>
</item><item>
<title>TCP Wrapper Documentation</title>
<description>I have a gentoo desktop profile system and I would like to use tcp wrappers to secure certain services like ssh. I followed the documentation I could</description>
<pubDate>09 Jan  2009 20:51:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/179151</link>
</item><item>
<title>[no subject]</title>
<description>gentoo-security+subscribe@lists.gentoo.org</description>
<pubDate>21 Oct  2008 04:23:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/174017</link>
</item><item>
<title>[no subject]</title>
<description></description>
<pubDate>21 Oct  2008 04:19:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/174016</link>
</item><item>
<title>Prince, Samuel is out of the office.</title>
<description>I will be out of the office starting 18/08/2008 and will not return until 29/08/2008. I will have limited access to my email while away from the off</description>
<pubDate>20 Aug  2008 20:03:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/170746</link>
</item><item>
<title>Reporting restricted bugs works again</title>
<description>Hello all, as you might be aware, the Gentoo Security Team encourages users to report security vulnerabilities or findings of code audits that are n</description>
<pubDate>20 Aug  2008 14:37:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/170739</link>
</item><item>
<title>[no subject]</title>
<description></description>
<pubDate>06 Aug  2008 07:12:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/security/170062</link>
</item>
</channel>
</rss>

