Commit Graph

183 Commits (debian-releases/etch.security)

Author SHA1 Message Date
Yaroslav Halchenko 42bb1e9e6c changelog entry 2009-02-05 11:18:19 -05:00
Yaroslav Halchenko dd17522d05 Updated urgency to high per instructions 2008-01-07 11:26:22 -05:00
Yaroslav Halchenko 27d4baeb55 BF: optional user= at the end for vsftpd. NOTE: given failregex would work only for etch shipped vsftpd/pam 2008-01-04 12:11:47 -05:00
Yaroslav Halchenko dce14c59d7 BF: fixed silly typo in sshd filter patch and extended vsftpd filter patch 2008-01-04 11:47:29 -05:00
Yaroslav Halchenko 7efdc417d6 building final submission to security team 2008-01-03 15:23:56 -05:00
Yaroslav Halchenko e8943c3a7b Merge branch 'maint/etch' into maint/etch.security
Conflicts:

	debian/changelog
2008-01-03 14:14:14 -05:00
Yaroslav Halchenko a4a03e5e63 adjusted changelog entry to mention CVE explicitely 2008-01-03 14:13:45 -05:00
Yaroslav Halchenko ca30745065 removed X00_rigid_usrbinpython patch per requrest from security team 2008-01-03 14:11:26 -05:00
Yaroslav Halchenko 41455bda75 just adusted mode on dpatch astime 2007-11-10 18:32:46 -05:00
Yaroslav Halchenko 143e53a764 * Anchored sshd and vsftpd failregex at the end of line to prevent DoS on
those services, which is related to CVE-2007-4321 and closed in sid
  438187.
2007-11-07 01:17:16 -05:00
Yaroslav Halchenko 398ae233b5 rigid call to python2.4 instead of relying on /usr/bin/env 2007-11-06 18:05:42 -05:00
Yaroslav Halchenko d4e0fc4a34 * Propagated "Fixed removal of host in hosts.deny" from 0.7.6, to prevent
possible DoS
2007-11-06 17:44:27 -05:00
Yaroslav Halchenko 996bfe13ed BF: Added patch 00_numeric_iptables-L to avoid possible DoS attacks
(introduced upstream in 0.7.6)
2007-11-06 15:03:59 -05:00
Yaroslav Halchenko 0e607fcf13 adjusted 00_close_log patch to apply over 0.7.5
added debian/changelog entries
boosted post-release revision
2007-11-06 14:50:23 -05:00
Yaroslav Halchenko 0a14d24216 tentative: propage patches 00_close_log and 00_reload from 0.7.8-1 2007-11-06 14:27:26 -05:00
Yaroslav Halchenko 066cce17f0 just added a not that it is not released yet 2007-08-16 02:55:22 +00:00
Yaroslav Halchenko d63c3c4aed * Propagated fix for asctime pattern from 0.7.8 release (closes: #421848) 2007-05-02 02:57:23 +00:00
Yaroslav Halchenko 14a2a45dbc releasing 2006-12-10 23:56:17 +00:00
Yaroslav Halchenko 762d1a188a * NEWS.Debian confusions - the latest NEWS entry and postinst message were
rephrased (Closes: #402350)
* Added mail-whois-lines action, which emails log lines containing abuser
  IP. Those lines are often required for proper abuse reports sent to the
  Internet providers.  Forwarding of such received emails to the email
  addresses of abuse departments present in the output of whois is a
  tentative solution for semi-automatic abuse reporting (Closes: #358810)
2006-12-10 23:40:04 +00:00
Yaroslav Halchenko bbb9e6f094 * NEWS.Debian confusions - the latest NEWS entry and postinst message
were rephrased (Closes: #402350)
2006-12-09 23:27:39 +00:00
Yaroslav Halchenko ae58ed091a * Removed obsolete patches left from 0.6
* Adjusted wsftpd patch to use <HOST> tag to be in line with the other
  filter definitions
2006-12-08 02:28:07 +00:00
Yaroslav Halchenko 1755dc2b0a updated the patch to the most recent release 2006-12-08 02:12:22 +00:00
Yaroslav Halchenko 7eac83b12d fresh upstream release 2006-12-08 01:21:42 +00:00
Yaroslav Halchenko 6d3c52a965 slightly corrected description for interpolations/parameters 2006-12-07 23:10:30 +00:00
Yaroslav Halchenko c46b9e0dca * README.Debian describes a bit issue of interpolations vs parameters passed
from jail.{conf,local} into an action or a filter definition (closes:
  #398739)
* Removed Uploaded field from control since I am a DD now. Big thanks to
  Barak Pearlmutter for being the sponsor of my packages for few
  years.
2006-12-07 13:20:51 +00:00
Yaroslav Halchenko 3a738497f8 * Added Suggests on mailx and relevant comments in README.Debian about
invoking mail actions (closes: #396668)
* Removed obsolete entries in TODO and README
* README.Debian describes a bit issue of interpolations vs parameters
  passed from jail.{conf,local} into an action or a filter definition
  (closes: #398739)
* Initial version of postfix filter (closes: #377711)
2006-12-07 04:07:59 +00:00
Yaroslav Halchenko ff491e48fa * Added debian/backports to contain patches necessary for backporting. It
gets used by pbuilder-ssh to create package for backports.org
2006-12-04 13:56:56 +00:00
Yaroslav Halchenko e46346d371 fixed name spoiled by on vaio 2006-11-12 02:20:32 +00:00
Yaroslav Halchenko 953f6c75b9 ready to buzz Barak 2006-11-12 02:18:47 +00:00
Yaroslav Halchenko b9b30341d4 * Cleaned up debian/rules a bit 2006-11-12 02:11:34 +00:00
Yaroslav Halchenko f8a3605c97 * "Clean" target removes generated .pyc files now (Closes: #398146) 2006-11-12 02:02:23 +00:00
Yaroslav Halchenko 97abba906f forgot to boost version 2006-11-11 00:11:59 +00:00
Yaroslav Halchenko 24ada3c63e * Only block new connects by using a new action iptables-new instead of
iptables (Closes: #350746)
* Updated README.Debian to reflect transition over to 0.7 branch and to
  comment on 350746
2006-11-11 00:10:10 +00:00
Yaroslav Halchenko 5cc9bc9ce6 made ~ version to accumulate more fixes before duploading 2006-11-10 15:56:58 +00:00
Yaroslav Halchenko 6a9ed3501a * Reincarnated logrotate configuration (Closes: #397878)
* no logrotation anymore? (Closes: #397878)
2006-11-10 15:54:34 +00:00
Yaroslav Halchenko f92a885d43 copied logrotate from 0.6 branch 2006-11-10 14:59:19 +00:00
Yaroslav Halchenko f4015e0c3c forgotten fi 2006-11-06 14:49:40 +00:00
Yaroslav Halchenko 28dad3752c * Warning NEWS entry for 0.7.1 was not shown during installation on test
boxes, thus postinst was adjusted accordingly to inform the user about the
  changes in the configuration files since 0.6.
2006-11-06 14:47:59 +00:00
Yaroslav Halchenko 6e1ec60318 put release to unstable 2006-11-06 14:29:56 +00:00
Yaroslav Halchenko b457f61e74 * Added reload/force-reload actions to init script
* Adjusted jail.conf a bit
2006-11-06 14:23:58 +00:00
Yaroslav Halchenko 2e568c08d6 new upstream 2006-11-02 02:04:57 +00:00
Yaroslav Halchenko 4bbea5b41b * Corrected init.d script to properly perform restart due to server delay to
react to client command to stop. Handling of status was adjusted as well
* Added apache-noscript to jail.conf
* Default action does not send emails to be inline with previous (0.6.x)
  behavior
2006-10-30 03:32:29 +00:00
Yaroslav Halchenko 668ef068cf * Fresh upstream: fixed a bug with not handling error producing
actioncheck call
2006-10-23 21:05:32 +00:00
Yaroslav Halchenko 1e4d6dd059 * debian/{rules,control} adjusted to conform all points in recent python
policy changes
* install under /usr/share instead of /usr/lib
2006-10-23 05:07:52 +00:00
Yaroslav Halchenko 6a2aaa4db7 * Adjusted rule to install man pages -- only .1 files since there are also
h2m sources
2006-10-23 04:49:52 +00:00
Yaroslav Halchenko 37d2abc8ea * Currrent snapshot of trunk
* Removed outdated (applied in 0.7.4 or specific for 0.6.?) patches
  from debian/patches
2006-10-23 04:45:34 +00:00
Yaroslav Halchenko 923d2214d9 added wuftpd to both 0.6 and 0.7 2006-10-18 05:15:53 +00:00
Yaroslav Halchenko 4ea2d8c370 few changelog entries 2006-10-02 19:28:23 +00:00
Yaroslav Halchenko 9851383362 fixed status command. now rely on presence of socket to be a bit more verbose 2006-10-02 19:27:30 +00:00
Yaroslav Halchenko a45fadd183 News about the 0.7 release and adjusted init script so it fails to start if not root 2006-10-02 19:03:58 +00:00