[Secure-testing-commits] r29008 - hardening

Guillaume Delacour kcd-guest at moszumanska.debian.org
Wed Sep 24 19:33:39 UTC 2014


Author: kcd-guest
Date: 2014-09-24 19:33:39 +0000 (Wed, 24 Sep 2014)
New Revision: 29008

Modified:
   hardening/subgoal-daemons.txt
Log:
Add other missing package such as pdns, knot, proftpd and document other fixed versions

Modified: hardening/subgoal-daemons.txt
===================================================================
--- hardening/subgoal-daemons.txt	2014-09-24 16:12:55 UTC (rev 29007)
+++ hardening/subgoal-daemons.txt	2014-09-24 19:33:39 UTC (rev 29008)
@@ -33,13 +33,10 @@
 busybox-syslogd
 crossfire
 ctrlproxy
-cvsd
 cyrus-imapd-2.2
 cyrus-imapd-2.4
 daemon
 daemontools
-dancer-ircd
-dancer-services
 dante
 dbndns
 dhis-dns-engine
@@ -51,7 +48,6 @@
 dnsproxy
 dsyslog
 dynamips
-eggdrop
 ekeyd
 ez-ipupdate
 fldigi
@@ -59,20 +55,16 @@
 gamin
 gammu
 gconf
-git
 gnome-keyring
 gnome-settings-daemon
 gpm
-gpsd
 gogoc
 hal
-haveged
 hdapsd
 hlbr
 httptunnel
 hybserv
 ibod
-icecast2
 ident2
 ifmail
 ifplugd
@@ -84,11 +76,8 @@
 inputlirc
 iodine
 ipband
-ircd-hybrid
-ircd-irc2
 ircd-ircu
 isakmpd
-iscsitarget
 isns
 kannel
 keynav
@@ -123,22 +112,18 @@
 muroard
 mxallowd
 mysql-5.1
-nagios3
 nas
 net-acct
 netatalk
 netplug
 nfs-utils
 ngetty
-ngircd
 notification-daemon
 notify-osd
 nuttcp
 obex-data-server
 oftc-hybrid
-open-iscsi
 openafs
-openbsd-inetd
 opencryptoki
 openvas-server
 p910nd
@@ -150,9 +135,7 @@
 ppp
 prayer
 preload
-privoxy
 pvm
-quagga
 radioclk
 radiusd-livingston
 randomsound
@@ -175,7 +158,6 @@
 swapspace
 synergy
 sysrqd
-sysstat
 sysvinit
 tcpspy
 telepathy-gabble
@@ -238,18 +220,31 @@
 clamsmtp	1.10-11, no pie and bindnow
 conntrack	1:1.2.1-1, no pie and bindnow
 consolekit	0.4.5-3, no pie and bindnow
+eggdrop		1.6.20-2 #668091, no pie and bindnow
 esmtp		1.2-7, no pie and bindnow
 fprobe		, no pie and bindnow
 gearmand	, no pie and bindnow
+git			1:1.7.7.2-1, no pie and bindnow
+gpsd		3.10+dev3~d6b65b48-3, relro not effective and not pie/bindnow
+haveged		1.7-1, no pie and bindnow
+icecast2	2.4.0-1, no pie and bindnow
+ircd-hybrid	1:7.2.2.dfsg.2-8, no pie and bindnow
+iscsitarget	1.4.20.2-7 #656867, no pie and bindnow
 mediatomb	0.12.1-4, no pie and bindnow
 memcached	1.4.13-0.1 #655134, no pie and bindnow
 miredo		1.2.6-1, no pie and bindnow
+ngircd		19.1-1 #664984, no pie and bindnow
+open-iscsi	659662, no LDFLAGS used, bug reopened
 net-snmp	5.7.2~dfsg-1~0.1, no pie
+pdns		3.1-1, no pie and bindnow
 perdition	1.19~rc5-1 #655412, no pie and bindnow
 polipo		1.0.4.1-1.2 #666451, no pie and bindnow
+proftpd		1.3.4a-2 #657213, no pie and bindnow
 ntp			1:4.2.6.p3+dfsg-2, no pie and bindnow
 pound		2.6-2 #654833, no pie and bindnow
+rpcbind		0.2.0-8, no pie and bindnow
 samba		2:3.5.11~dfsg-2, no pie and bindnow
+sysstat		9.1.7-2, no pie and bindnow
 trafficserver 3.0.2-1
 tcpd		7.6.q-22, no pie and bindnow
 tor			0.2.2.7-alpha-2
@@ -268,6 +263,7 @@
 bluez
 collectd	4.10.7-1 #656271
 cron            3.0pl1-121
+cvsd		1.0.24 #662226
 dbus		1.5.10-1
 dovecot		1:2.0.18-1 #653530
 dnsmasq		2.62-1
@@ -277,22 +273,28 @@
 haproxy	
 inetutils 	2:1.9-1
 inspircd	2.0.5-0.1
+ircd-irc2	2.11.2p3~dfsg-1
+ircd-ratbox	3.0.7.dfsg-2 #664903
 isc-dhcp        4.2.2-2
+knot		1.5.1-2
 krb5		1.10+dfsg~beta1-1 #655248
 lighttpd	1.4.30-1
 loqui		0.5.1-2
 memcachedb	1.2.0-9
-minidlna 1.0.25+dfsg-1
+minidlna	1.0.25+dfsg-1
+nagios3		3.2.3-2 (hardening-wrapper used)
 nagios-plugins	1.4.15-5
 nbd		1:3.0-1
 nfdump
 nginx		1.1.14-1
 nsd			3.2.9-3
+openbsd-inetd	0.20140418-1
 openldap	2.4.25-4 #644427
 openssh		1:5.2p1-1
 openvpn		2.2.1-4
 pcsc-lite	1.8.2-1
 postfix		2.5.4-2
+privoxy		3.0.19-2
 rsyslog		5.8.6-1 #644303
 rsync		3.1.1-1
 solid-pop3d	0.15-25
@@ -311,6 +313,7 @@
 xdm		1:1.1.11-1
 w3m             0.5.3-5
 radvd		1:1.9.1-1.1 #665715
+quagga		0.99.22.4-3
 redis		2:2.8.14-1 #760567
 slony1-2
 sniffit         0.3.7.beta-17 (#649817)
@@ -318,4 +321,5 @@
 
 Not relevant:
 sks             ocaml
-
+dancer-ircd		removed from the archive (#717164)
+dancer-services	removed from the archive




More information about the Secure-testing-commits mailing list