Re: CVE (Critical + High) in bookworm image

2023-11-22 Thread David Wright
On Wed 22 Nov 2023 at 15:27:06 (-0500), Greg Wooledge wrote: > On Wed, Nov 22, 2023 at 01:34:49PM -0600, David Wright wrote: > > AFAICT zipOpenNewFileInZip4_64 is only contained in > > /usr/lib/x86_64-linux-gnu/libminizip.so.1.0.0 which is from package > > libminizip1_1~b1_amd64.deb. > > > > In De

Re: CVE (Critical + High) in bookworm image

2023-11-22 Thread Greg Wooledge
On Wed, Nov 22, 2023 at 01:34:49PM -0600, David Wright wrote: > AFAICT zipOpenNewFileInZip4_64 is only contained in > /usr/lib/x86_64-linux-gnu/libminizip.so.1.0.0 which is from package > libminizip1_1~b1_amd64.deb. > > In Debian, it would appear that minizip was split off from zlib1g > a decade a

Re: CVE (Critical + High) in bookworm image

2023-11-22 Thread David Wright
On Wed 22 Nov 2023 at 12:52:17 (-0500), Greg Wooledge wrote: > On Wed, Nov 22, 2023 at 10:39:56PM +0530, thomas wrote: > > is there any way we could get > > a fix in bookworm release or is there any other suggestion. > > Whenever the security team releases a fix. > > > CVE-2023-45853 > > https:/

Re: CVE (Critical + High) in bookworm image

2023-11-22 Thread Greg Wooledge
On Wed, Nov 22, 2023 at 10:39:56PM +0530, thomas wrote: > is there any way we could get > a fix in bookworm release or is there any other suggestion. Whenever the security team releases a fix. > CVE-2023-45853 https://security-tracker.debian.org/tracker/CVE-2023-45853 "MiniZip in zlib through

CVE (Critical + High) in bookworm image

2023-11-22 Thread thomas
Hi, I am installing nodejs on top of a debian (bookworm-slim) image for some task. While the intended functionality works fine, the security scan (JFrog Xray) fails with a critical and high issue. I see some fix in sid but since it is development mode (I believe) is there any way we could get

Re: Part II dd copy destroyed DVD

2023-11-22 Thread to...@tuxteam.de
On Wed, Nov 22, 2023 at 02:11:13PM +, Schwibinger Michael wrote: > > Yes. > This is the problem. > So mc cannot copy all files Perhaps. But perhaps not. It is possible we misunderstand. Can you please - show us the file name you are trying to copy the ISO to? Please, with the full path.

AW: Part II dd copy destroyed DVD

2023-11-22 Thread Schwibinger Michael
Yes. This is the problem. So mc cannot copy all files Regards Sophie Von: to...@tuxteam.de Gesendet: Sonntag, 19. November 2023 06:59 Bis: Timothy M Butterworth Cc: debian-user@lists.debian.org Betreff: Re: Part II dd copy destroyed DVD On Sat, Nov 18, 2023 a

Re: it: perhaps? gmail issues.

2023-11-22 Thread Richmond
In this article Google seems to think using standard webmail works with a screen reader. https://support.google.com/mail/answer/90559 It advises to turn on keyboard shortcuts. I suppose another option would be to use another webmail service to pick up email from gmail. Karen Lewellen wrote: > H

Re: bash vs. dash and stdin

2023-11-22 Thread Nicolas George
Max Nikulin (12023-11-22): > Is there a document that describes shell behavior in respect to stdin in > such cases? The shell did not eat your stdin here, ssh did. Regards, -- Nicolas George

Re: bash vs. dash and stdin

2023-11-22 Thread Greg Wooledge
On Wed, Nov 22, 2023 at 07:06:58PM +0700, Max Nikulin wrote: > Consider a file (ssh.sh) containing a couple of commands: > >ssh localhost echo remote >echo local > > Let's try to run it (assuming key-based authorization) > > bash remote You're trying to use stdin twice at the s

bash vs. dash and stdin

2023-11-22 Thread Max Nikulin
Hi, There was a thread on stdio buffering and fork a month ago. That time I thought shells should be rather careful with input/output handling when spawning subprocesses. Consider a file (ssh.sh) containing a couple of commands: ssh localhost echo remote echo local Let's try to run it

Re: Weird MAC address

2023-11-22 Thread Marco Moock
Am 22.11.2023 um 12:00:52 Uhr schrieb Nicolas George: > Thanks for clarifying. But AFAIK, with proxy ARP, the network mask > covers all the networks covered by the proxy. That is not the case > here. Does your Router have a default route? The it covers 0.0.0.0/0.

Re: Weird MAC address

2023-11-22 Thread Marco Moock
Am 22.11.2023 um 11:58:55 Uhr schrieb Nicolas George: > I do not see what the router has to do with anything. Can you > elaborate what you mean? Proxy-ARP offers the possibility to answer ARP requests of addresses outside the own subnet sitting on another ethernet link. In normal cases that is no

Re: Weird MAC address

2023-11-22 Thread Nicolas George
Marco Moock (12023-11-22): > Sorry, not gracious-arp, proxy-arp can be responsible for that. Thanks for clarifying. But AFAIK, with proxy ARP, the network mask covers all the networks covered by the proxy. That is not the case here. Regards, -- Nicolas George

Re: Weird MAC address

2023-11-22 Thread Nicolas George
Marco Moock (12023-11-22): > Are those networks on the same ethernet link? No, they are on a different VLAN. > Are some systems with wrong subnet masks on the link and the router has > gratious ARP enabled? I do not see what the router has to do with anything. Can you elaborate what you mean? O

Re: Weird MAC address

2023-11-22 Thread Marco Moock
Am 22.11.2023 um 11:51:36 Uhr schrieb Marco Moock: > Are some systems with wrong subnet masks on the link and the router > has gratious ARP enabled? Sorry, not gracious-arp, proxy-arp can be responsible for that.

Re: Weird MAC address

2023-11-22 Thread Marco Moock
Am 22.11.2023 um 11:29:47 Uhr schrieb Nicolas George: > As you can see, the server is on the …96.0/22 subnet, i.e. …96-…99, > but it sees MAC addresses on the 100 and 103 networks. Are those networks on the same ethernet link? Are some systems with wrong subnet masks on the link and the router ha

Weird MAC address

2023-11-22 Thread Nicolas George
Hi. Since last we have four MAC addresses in the ARP table of a server that should not be there: $ ip route default via XXX.XXX.98.254 dev eth0 onlink XXX.XXX.96.0/22 dev eth0 proto kernel scope link src XXX.XXX.98.94 But: $ ip neigh | grep -v 'XXX.XXX.9[6789]' XXX.XXX.103.161 dev eth0 lla

Re: screen lock shuts down attached HDDs, they don't start up again

2023-11-22 Thread Zenaan Harkness
addy, but the hdd remains in a > spun down/ sleep state, and no /dev/sd* device. I apologize, the above para was inserted after I did the suspend and wake cycle, and the following paras were done before that. I apologize for the confusion, so just be aware the following paras are part of the

Re: screen lock shuts down attached HDDs, they don't start up again

2023-11-22 Thread Zenaan Harkness
isk/|grep usb /dev/disk/by-id/usb-WDC_WD20_SPZX-22UA7T0_RANDOM__3F4917AD758C-0:0 /dev/disk/by-path/pci-:3a:00.0-usb-0:2.3.1:1.0-scsi-0:0:0:0 # ll /dev/disk/by-path/pci-:3a:00.0-usb-0:2.3.1:1.0-scsi-0:0:0:0 0 lrwxrwxrwx 1 root root 9 20231122 10:33.10 /dev/disk/by-path/pci-:3a:00.0-usb-0