Re: privilege escalation and potential data loss in logrotate

2010-12-11 Thread Florian Zumbiehl
Hi, > On Samstag, 11. Dezember 2010, Florian Zumbiehl wrote: > > I was up to, plus anyone on d-qa who read my mail there also could have > > pointed me in the right direction, so I won't take the blame for that. > > I've read your mail to debian-qa some weeks a

Re: Bug#606543: clamav-freshclam: affected by privilege escalation vulnerability in logrotate

2010-12-10 Thread Florian Zumbiehl
Hi, > On Fri, Dec 10, 2010 at 9:43 AM, Michael Tautschnig wrote: > >> These lines from this package's maintainer scripts suggest that it likely > >> is affected by the vulnerability: > >> > >> --- > >> chmod 640 $FRESHCLAMLOG

Re: Bug#606543: clamav-freshclam: affected by privilege escalation vulnerability in logrotate

2010-12-10 Thread Florian Zumbiehl
Hi, > [...] > > > > These lines from this package's maintainer scripts suggest that it likely > > is affected by the vulnerability: > > > > --- > > chmod 640 $FRESHCLAMLOGFILE > > chown "$dbowner":adm $FRESHCLAMLOGFILE > > -

Re: privilege escalation and potential data loss in logrotate

2010-12-10 Thread Florian Zumbiehl
Hi, > (copying the thread to debian-devel, where mass-bug-fills *has to* be > discussed, not d-qa) As such I would suggest completely moving this thread over to d-devel and dropping d-qa from subsequent mails. [...] > > If I don't see any solution emerging in a reasonable time frame, my next > >

Re: privilege escalation and potential data loss in logrotate

2010-12-10 Thread Florian Zumbiehl
Hi, > On Fri, Dec 10, 2010 at 10:17:53AM +0100, Sandro Tosi wrote: > > > If you really care about this problem, which is nice, try to get > > logrotate fixed. > > As I have said before, I do welcome patches that don't break existing > functionality or introduce new race conditions. Let me quote

Re: Another load of typos

2005-03-16 Thread Florian Zumbiehl
Hi, my current plans are now as follows: Submit maint-only bug reports regarding "a" vs. "an" for the following "words", including a reference to this thread in the mailing list archive: > ACPI > Adlib > AX.25 > EsounD > FLTK > FPU > FTP > IETF > IMAP > Internet > IP > IPv4 > IPv6 > IR > IrDA > I

Re: Another load of typos

2005-03-16 Thread Florian Zumbiehl
Hi, > > now that the problems with my last bunch of bug reports on mostly "its" > > vs. "it's" mistakes some months ago seem to be solved, I've found another > > load of typos of the "a" vs. "an" flavor, about 110 in total. > > please please please...for anything which can be localized (especiall

Re: Another load of typos

2005-03-14 Thread Florian Zumbiehl
Hi, > > The rule I am following is that "a" vs. "an" is decided by pronounciation > > only - i.e., it's "an eff ey kju", but "a FAT file system". After all, > > that's how the exact letters are most easily read (without expanding > > acronyms or such). > > Your rule is correct: it is determined b

Re: Another load of typos

2005-03-14 Thread Florian Zumbiehl
Hi, > > To verify that what I think to be incorrect really is, here is the list > > of "words" I've found to be used with "a" but which I think should be > > used with "an": > > > > FAQ > > Would you mind giving a reference to a manual of style or something > about these? I always only use "an"

Another load of typos

2005-03-14 Thread Florian Zumbiehl
Hi, now that the problems with my last bunch of bug reports on mostly "its" vs. "it's" mistakes some months ago seem to be solved, I've found another load of typos of the "a" vs. "an" flavor, about 110 in total. Now my questions are as follows: - Anything I should do differently when reporting t