summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-dev/20110524/004930.html
diff options
context:
space:
mode:
authorNicolas Vigier <boklm@mageia.org>2013-04-14 13:46:12 +0000
committerNicolas Vigier <boklm@mageia.org>2013-04-14 13:46:12 +0000
commit1be510f9529cb082f802408b472a77d074b394c0 (patch)
treeb175f9d5fcb107576dabc768e7bd04d4a3e491a0 /zarb-ml/mageia-dev/20110524/004930.html
parentfa5098cf210b23ab4f419913e28af7b1b07dafb2 (diff)
downloadarchives-1be510f9529cb082f802408b472a77d074b394c0.tar
archives-1be510f9529cb082f802408b472a77d074b394c0.tar.gz
archives-1be510f9529cb082f802408b472a77d074b394c0.tar.bz2
archives-1be510f9529cb082f802408b472a77d074b394c0.tar.xz
archives-1be510f9529cb082f802408b472a77d074b394c0.zip
Add zarb MLs html archivesHEADmaster
Diffstat (limited to 'zarb-ml/mageia-dev/20110524/004930.html')
-rw-r--r--zarb-ml/mageia-dev/20110524/004930.html99
1 files changed, 99 insertions, 0 deletions
diff --git a/zarb-ml/mageia-dev/20110524/004930.html b/zarb-ml/mageia-dev/20110524/004930.html
new file mode 100644
index 000000000..6b5adea1a
--- /dev/null
+++ b/zarb-ml/mageia-dev/20110524/004930.html
@@ -0,0 +1,99 @@
+<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
+<HTML>
+ <HEAD>
+ <TITLE> [Mageia-dev] slight security improvement: should we update aria2 to 1.11.2?
+ </TITLE>
+ <LINK REL="Index" HREF="index.html" >
+ <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20slight%20security%20improvement%3A%20should%20we%20update%0A%20aria2%20to%201.11.2%3F&In-Reply-To=%3C1306225040.3942.13.camel%40akroma.ephaone.org%3E">
+ <META NAME="robots" CONTENT="index,nofollow">
+ <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
+ <LINK REL="Previous" HREF="004929.html">
+ <LINK REL="Next" HREF="004934.html">
+ </HEAD>
+ <BODY BGCOLOR="#ffffff">
+ <H1>[Mageia-dev] slight security improvement: should we update aria2 to 1.11.2?</H1>
+ <B>Michael Scherer</B>
+ <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20slight%20security%20improvement%3A%20should%20we%20update%0A%20aria2%20to%201.11.2%3F&In-Reply-To=%3C1306225040.3942.13.camel%40akroma.ephaone.org%3E"
+ TITLE="[Mageia-dev] slight security improvement: should we update aria2 to 1.11.2?">misc at zarb.org
+ </A><BR>
+ <I>Tue May 24 10:17:20 CEST 2011</I>
+ <P><UL>
+ <LI>Previous message: <A HREF="004929.html">[Mageia-dev] slight security improvement: should we update aria2 to 1.11.2?
+</A></li>
+ <LI>Next message: <A HREF="004934.html">[Mageia-dev] slight security improvement: should we update aria2 to 1.11.2?
+</A></li>
+ <LI> <B>Messages sorted by:</B>
+ <a href="date.html#4930">[ date ]</a>
+ <a href="thread.html#4930">[ thread ]</a>
+ <a href="subject.html#4930">[ subject ]</a>
+ <a href="author.html#4930">[ author ]</a>
+ </LI>
+ </UL>
+ <HR>
+<!--beginarticle-->
+<PRE>Le mardi 24 mai 2011 &#224; 10:07 +0200, Thierry Vignaud a &#233;crit :
+&gt;<i> Hi
+</I>&gt;<i>
+</I>&gt;<i> We are currently shiping aria2-1.11.1.
+</I>&gt;<i>
+</I>&gt;<i> However latest version is 1.11.2 which slightly improve security when
+</I>&gt;<i> using authenticated
+</I>&gt;<i> media by hiding them from process viewers (ps, ...):
+</I>&gt;<i>
+</I>&gt;<i> <A HREF="http://sourceforge.net/news/?group_id=159897">http://sourceforge.net/news/?group_id=159897</A>
+</I>&gt;<i> &quot;The username and password specified in command-line are now masked with
+</I>&gt;<i> &quot;*&quot; immediately after parsed, so that ps cannot show username and password.&quot;
+</I>&gt;<i>
+</I>&gt;<i> Since that does not happen for most users and since we don't provide auth media,
+</I>&gt;<i> that's not a immediate concern, so should we update for Mageia 1?
+</I>
+I would keep this as a update after the release is out ( like they 4
+ruby cve, libzip one ( CVE-2011-0421 )) and others that came out since
+yesterday.
+
+So maybe we could open bugs for this ?
+
+There is 2 proposal :
+- filling them on security, and have a saved search
+- creating a tracker bug
+
+I would be in favor of the tracker bug :
+- you can subscribe to it
+- it will be clearer ( as bugfixes are not security so we may miss some
+update to do )
+- it doesn't pollute the list of saved search
+
+But as pascal said, a tracker bug requires that each bug to be linked to
+it, which is manual and error prone.
+
+Any opinion on this ( or a 3rd proposal ) ?
+
+--
+Michael Scherer
+
+</PRE>
+
+
+
+
+
+<!--endarticle-->
+ <HR>
+ <P><UL>
+ <!--threads-->
+ <LI>Previous message: <A HREF="004929.html">[Mageia-dev] slight security improvement: should we update aria2 to 1.11.2?
+</A></li>
+ <LI>Next message: <A HREF="004934.html">[Mageia-dev] slight security improvement: should we update aria2 to 1.11.2?
+</A></li>
+ <LI> <B>Messages sorted by:</B>
+ <a href="date.html#4930">[ date ]</a>
+ <a href="thread.html#4930">[ thread ]</a>
+ <a href="subject.html#4930">[ subject ]</a>
+ <a href="author.html#4930">[ author ]</a>
+ </LI>
+ </UL>
+
+<hr>
+<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev
+mailing list</a><br>
+</body></html>