[Secure-testing-commits] r28878 - hardening

Guillaume Delacour kcd-guest at moszumanska.debian.org
Wed Sep 17 20:27:00 UTC 2014


Author: kcd-guest
Date: 2014-09-17 20:26:59 +0000 (Wed, 17 Sep 2014)
New Revision: 28878

Modified:
   hardening/subgoal-daemons.txt
Log:
Add missing daemons (mdadm, unbound, nsd, rsync, etc..) and document fixed/partially fixed versions

Modified: hardening/subgoal-daemons.txt
===================================================================
--- hardening/subgoal-daemons.txt	2014-09-17 20:24:19 UTC (rev 28877)
+++ hardening/subgoal-daemons.txt	2014-09-17 20:26:59 UTC (rev 28878)
@@ -18,25 +18,19 @@
 To check:
 
 ample
-amule
 and
 archfs
-autofs
-autossh
 avr-evtd
 bacula
 bandwidthd
 bcron
 beanstalkd
 binkd
-bird
 bitlbee
 bluemon
-bluez
 boa
 bozohttpd
 busybox-syslogd
-c-icap
 crossfire
 ctrlproxy
 cvsd
@@ -59,7 +53,6 @@
 dynamips
 eggdrop
 ekeyd
-esmtp
 ez-ipupdate
 fldigi
 freepops
@@ -118,11 +111,11 @@
 maradns
 masqmail
 mathopd
+mdadm
 micro-httpd
 milter-greylist
 mini-httpd
 minit
-miredo
 mmpong
 moc
 mpd
@@ -133,7 +126,6 @@
 nagios3
 nas
 net-acct
-net-snmp
 netatalk
 netplug
 nfs-utils
@@ -231,25 +223,38 @@
 fair (#725360)
 
 Partially fixed:
+acpi		1:2.0.14-2 #653502 , no pie and bindnow
+amule		2.3.1-2 #653503, no pie and bindnow
 asterisk	1:1.8.8.2~dfsg-1 #653944, hardening flags disabled since 1:11.5.1~dfsg-1
+autossh		1.4c-2
+autofs		5.0.6-3
 balance		, no pie and bindnow
 bip			0.8.9-1, need only bindnow
 cfengine2	, FTBFS with -Werror=format-security
 cfengine3	, FTBFS with -Werror=format-security
+c-icap		1:0.3.1-1, no pie and bindow
 cherokee, removed from the archive
+clamav		0.97.5+dfsg-1 #653958, no pie and bindnow
 clamsmtp	1.10-11, no pie and bindnow
+conntrack	1:1.2.1-1, no pie and bindnow
 consolekit	0.4.5-3, no pie and bindnow
+esmtp		1.2-7, no pie and bindnow
 fprobe		, no pie and bindnow
-conntrack	1:1.2.1-1, no pie and bindnow
+gearmand	, no pie and bindnow
 mediatomb	0.12.1-4, no pie and bindnow
 memcached	1.4.13-0.1 #655134, no pie and bindnow
+miredo		1.2.6-1, no pie and bindnow
+net-snmp	5.7.2~dfsg-1~0.1, no pie
 perdition	1.19~rc5-1 #655412, no pie and bindnow
+polipo		1.0.4.1-1.2 #666451, no pie and bindnow
 ntp			1:4.2.6.p3+dfsg-2, no pie and bindnow
 pound		2.6-2 #654833, no pie and bindnow
-varnish		3.0.2-2 #663064, no pie and bindnow
+samba		2:3.5.11~dfsg-2, no pie and bindnow
 trafficserver 3.0.2-1
 tcpd		7.6.q-22, no pie and bindnow
 tor			0.2.2.7-alpha-2
+varnish		3.0.2-2 #663064, no pie and bindnow
+vpnc		0.5.3r512-1, no pie and bindnow
 
 Resolved/fixed:
 aiccu           20070115-15 #644408
@@ -259,6 +264,8 @@
 at			3.1.13-2
 avahi
 bind9		1:9.5.0.dfsg.P2-2
+bird		1.3.11-4
+bluez
 collectd	4.10.7-1 #656271
 cron            3.0pl1-121
 dbus		1.5.10-1
@@ -269,6 +276,7 @@
 freeradius	2.1.12+dfsg-1 #657838
 haproxy	
 inetutils 	2:1.9-1
+inspircd	2.0.5-0.1
 isc-dhcp        4.2.2-2
 krb5		1.10+dfsg~beta1-1 #655248
 lighttpd	1.4.30-1
@@ -279,12 +287,14 @@
 nbd		1:3.0-1
 nfdump
 nginx		1.1.14-1
+nsd			3.2.9-3
 openldap	2.4.25-4 #644427
 openssh		1:5.2p1-1
 openvpn		2.2.1-4
 pcsc-lite	1.8.2-1
 postfix		2.5.4-2
 rsyslog		5.8.6-1 #644303
+rsync		3.1.1-1
 solid-pop3d	0.15-25
 squid		2.7.STABLE7-1
 squid3		partial
@@ -296,10 +306,10 @@
 tinyproxy	1.8.3-2
 transmission-daemon 2.51-2 #671569
 trousers	0.3.8-1
+unbound		1.4.16-2 #658021
 vsftpd		2.3.5-2 #644295
 xdm		1:1.1.11-1
 w3m             0.5.3-5
-inspircd	2.0.5-0.1
 radvd		1:1.9.1-1.1 #665715
 redis-server 2:2.8.14-1 #760567
 slony1-2




More information about the Secure-testing-commits mailing list