Search This Blog

Friday, December 28, 2007

[SECURITY] [DSA 1438-1] New tar packages fix several vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1438-1 security@debian.org
http://www.debian.org/security/

Florian Weimer
December 28, 2007

http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package : tar
Vulnerability : several
Problem type : local(remote)
Debian-specific: no
CVE Id(s) : CVE-2007-4131, CVE-2007-4476

Several vulnerabilities have been discovered in GNU Tar. The Common
Vulnerabilities and Exposures project identifies the following problems:

CVE-2007-4131

A directory traversal vulnerability enables attackers using
specially crafted archives to extract contents outside the
directory tree created by tar.

CVE-2007-4476

A stack-based buffer overflow in the file name checking code may
lead to arbitrary code execution when processing maliciously
crafted archives.

For the stable distribution (etch), these problems have been fixed in
version 1.16-2etch1.

For the old stable distribution (sarge), these problems have been
fixed in 1.14-2.4.

For the unstable distribution (sid), these problems have been fixed in
version 1.18-2.

We recommend that you upgrade your tar package.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian 3.1 (oldstable)
- ----------------------

Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc.

Source archives:

http://security.debian.org/pool/updates/main/t/tar/tar_1.14.orig.tar.gz

Size/MD5 checksum: 1485633 3094544702b1affa32d969f0b6459663

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4.dsc

Size/MD5 checksum: 846 cbcbbd7c638de842f913ac566c3f0b0a

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4.diff.gz

Size/MD5 checksum: 51869 2675ec9acdf59ba6f0c54e5325675fcf

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_alpha.deb

Size/MD5 checksum: 533650 c5e87a25f7c6efd0e39647249f889ca3

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_amd64.deb

Size/MD5 checksum: 504092 64131456790b8bc4b45e341ce0ca6040

arm architecture (ARM)

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_arm.deb

Size/MD5 checksum: 502452 1374822a67eafcd4f385b43479225b7b

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_hppa.deb

Size/MD5 checksum: 517962 f8d1d70a5989d1cab377efdc7c821e24

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_i386.deb

Size/MD5 checksum: 500822 3b1099df9c1df15768f8dc568068e02f

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_ia64.deb

Size/MD5 checksum: 543620 3026d8ed3c4e9203b3af8e7813a7858c

m68k architecture (Motorola Mc680x0)

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_m68k.deb

Size/MD5 checksum: 489264 ec8bab9c3860d11e33b4c5ebef3be8e0

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_mips.deb

Size/MD5 checksum: 520658 9211a627bc4bd7859bf8e3c538abf342

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_mipsel.deb

Size/MD5 checksum: 520438 a58746324064e51070a558102a134de3

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_powerpc.deb

Size/MD5 checksum: 507092 bd57425832d21b0a12843d196c2ba4f0

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_s390.deb

Size/MD5 checksum: 512130 cd095e0a66981c279d8d1ede88c67a60

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/t/tar/tar_1.14-2.4_sparc.deb

Size/MD5 checksum: 499878 062c6de1a4b1b5a0ea9da2926f5d80ec

Debian 4.0 (stable)
- -------------------

Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1.diff.gz

Size/MD5 checksum: 31360 96eb9bcd2d8257893a4f530eb00c9da5

http://security.debian.org/pool/updates/main/t/tar/tar_1.16.orig.tar.gz

Size/MD5 checksum: 2199571 d971b9d6114ad0527ef89fab0d3167e0

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1.dsc

Size/MD5 checksum: 871 c7d9d75758a04174348cd65bb7aaab16

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_alpha.deb

Size/MD5 checksum: 738546 c181b637bb4ed83619c0086bb3d19312

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_amd64.deb

Size/MD5 checksum: 714108 b7287060cfefae808c694a60f9cb421c

arm architecture (ARM)

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_arm.deb

Size/MD5 checksum: 671036 c20ed223967ec38af1ddf88d1b49eff9

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_hppa.deb

Size/MD5 checksum: 695748 69013bb176a94d2ef6d17342728ed3f8

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_i386.deb

Size/MD5 checksum: 675590 5630796721944b8f6c261628b0f2b18d

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_ia64.deb

Size/MD5 checksum: 807488 0e4fd97fd5fef6a0b4fd6edba44ec9ca

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_mips.deb

Size/MD5 checksum: 701392 c627d531a2d02d652a8fb220f90e51e1

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_mipsel.deb

Size/MD5 checksum: 701162 979cdb4ee29782a1b9fa1d68c5de05ee

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_powerpc.deb

Size/MD5 checksum: 683616 73c25ecbdbf6aac0c814b1b16cdf99ab

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_s390.deb

Size/MD5 checksum: 694000 2364d67dcc6eb6b160590189fa4553ad

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/t/tar/tar_1.16-2etch1_sparc.deb

Size/MD5 checksum: 668548 ec9e0a954b64ca8cbf8af1412870b8d8


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHdRYaXm3vHE4uyloRAnSyAJ9dEJXC7FpkU3NQtJnCImo0doUnnwCeMZWk
gUArnuL3rSP2xir89rWWpyg=
=y/nl
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Thursday, December 27, 2007

Dear Loved One

From: Lady Fatima Ali H Kasali,
33-35
Greenwich Church Street ,
London SE10 9BJ ,
England.
 
 
Here writes Lady Fatima Ali H Kasali , suffering from cancerous ailment. I am a widow , My late husband is Engineer Ali H Kasali a Malaysian. He was into private practice all his life before his death. Our life together as man and wife lasted for two decades without child. My husband died after a protracted illness.My husband and I made a vow to uplift the down-trodden and the less-privileged individuals, as he had passion for people who can not help
themselves due to physical disability or financial predicament. I can
adduce this to the fact that he needed a Child from this relationship,
which never came.
When my late husband was alive he deposited the sum of
5,600,000 (Five Million, Six Hundred Thousand Great Britain Pounds Sterling), which were derived from his vast estates and investment in capital market. Presently, this money is still with the
Bank.
 
Recently, my Doctor told me that I have limited days to live, due to
the cancerous problems I am suffering from. Though what b
urders
me most is the stroke that I have in addition to this cancer. With this
hard reality that has befallen my family
,
I have decided to donate this fund to you, and want you to use this gift which comes from
my husbands effort to fund the upkeep of widows, widowers, orphans,
destitu
tes,
physically challenged children, barren-women and persons who prove to be genuinely handicapped financially.It is often said that, givers, never lack. I took this decision because I do not have any child that will inherit this money and my husband's relatives are bourgeois and are very wealthy, and I do not want my husbands hard earned money to be missused or invested into ill perceived ventures.
 
I do not want a situation where this money will be used contrary to the stipulated agreement. I am not afraid of death hence I know where I am going. With Allah, all things are possible. As soon as I receive your reply, I shall give you the contact of the bank in Malaysia. I will also issue you a Letter of Authority
that will empower you as the original beneficiary of this fund via my
Lawyer. My happiness is that I lived a life worthy of emulation.
Please always be
focused
all through your life. Please assure me
that you will act just as I have stated herein. Hope to hear from you
soon
, and Allah be with you and members of your family. Y
ou can contact me through my private email address: ladyfatimahkasali@myway.com
 
Warm Regard, 
Lady Fatima Ali H Kasali,


Looking for last minute shopping deals? Find them fast with Yahoo! Search.

[SECURITY] [DSA 1405-3] New zope-cmfplone packages fix regression

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1405-3 security@debian.org
http://www.debian.org/security/

Thijs Kinkhorst
December 1st, 2007

http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package : zope-cmfplone
Vulnerability : missing input sanitising
Problem-Type : remote
Debian-specific: no
CVE ID : CVE-2007-5741
Debian Bug : 449523

The Plone developers discovered that their hotfix, released as DSA 1405,
introduced two regressions. This update corrects these flaws. For
completeness, the original advisory text below:

It was discovered that Plone, a web content management system, allows
remote attackers to execute arbitrary code via specially crafted web
browser cookies.

The oldstable distribution (sarge) is not affected by this problem.

For the stable distribution (etch) this problem has been fixed in
version 2.5.1-4etch3.

For the unstable distribution (sid) this problem has been fixed in
version 2.5.2-3.

We recommend that you upgrade your zope-cmfplone package.

Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

Source archives:

http://security.debian.org/pool/updates/main/z/zope-cmfplone/zope-cmfplone_2.5.1.orig.tar.gz

Size/MD5 checksum: 1064993 b48215d46aafa9e1f12196263d86a191

http://security.debian.org/pool/updates/main/z/zope-cmfplone/zope-cmfplone_2.5.1-4etch3.diff.gz

Size/MD5 checksum: 11282 5333207df578b0ddfe05207225b09e76

http://security.debian.org/pool/updates/main/z/zope-cmfplone/zope-cmfplone_2.5.1-4etch3.dsc

Size/MD5 checksum: 1114 73489e05e1e2c706a70279e50759b7c5

Architecture independent packages:

http://security.debian.org/pool/updates/main/z/zope-cmfplone/plone-site_2.5.1-4etch3_all.deb

Size/MD5 checksum: 9956 105cbe8680cf1da7956b7a201d53df1f

http://security.debian.org/pool/updates/main/z/zope-cmfplone/zope-cmfplone_2.5.1-4etch3_all.deb

Size/MD5 checksum: 1190972 68583a0c4662b6fd8f19e01cdf4b0f9b


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHdBbrXm3vHE4uyloRAjRpAJ9Prr7B3TzrmXdrarbQPX5j7YBVXgCaAsA9
gjndfocJs3tohfwL/rNbT0g=
=xil9
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

firewall-wizards Digest, Vol 20, Issue 13

Send firewall-wizards mailing list submissions to
firewall-wizards@listserv.icsalabs.com

To subscribe or unsubscribe via the World Wide Web, visit
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
or, via email, send a message with subject or body 'help' to
firewall-wizards-request@listserv.icsalabs.com

You can reach the person managing the list at
firewall-wizards-owner@listserv.icsalabs.com

When replying, please edit your Subject line so it is more specific
than "Re: Contents of firewall-wizards digest..."


Today's Topics:

1. Re: PIX access-list help (Brian Blater)
2. Re: Anyone have any informed opinions on the Watchguard
product line? (Jim Seymour)


----------------------------------------------------------------------

Message: 1
Date: Wed, 26 Dec 2007 13:07:37 -0500
From: "Brian Blater" <brb.lists@gmail.com>
Subject: Re: [fw-wiz] PIX access-list help
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID:
<7743536a0712261007ic01f92fm562685817ecd9e0a@mail.gmail.com>
Content-Type: text/plain; charset=ISO-8859-1

On Dec 25, 2007 12:25 AM, Paul Melson <pmelson@gmail.com> wrote:
> On Dec 21, 2007 11:02 AM, Brian Blater <brb.lists@gmail.com> wrote:
> > So, my main question, is there an access list command I can have that
> > basically says "allow all communication from the dmz to the internet"
> > and one that says "allow communication from the inside to the dmz"? I
> > know I can add "access-list dmz permit ip host 192.168.1.1 any" and
> > that solves the problem of getting to the internet, but then it opens
> > all communication to the inside from this host and I don't want to do
> > that. Since this is version 6.3(3) I can't use an out access-list
> > which I think might solve the problem. I have enough memory to run
> > version 7.x on this PIX, but I'm trying to tackle one problem at a
> > time and I'm a little hesitant about doing the 7.x upgrade just yet.
>
> The short answer to your question is that PIX access-lists are read,
> per-interface, top-to-bottom:
>
> access-list dmz_in deny ip 192.168.1.0 255.255.255.0 10.0.0.0 255.0.0.0
> access-list dmz_in permit ip 192.168.1.0 255.255.255.0 any
> access-group dmz_in in interface dmz
>
> If your internal network is 10.0.0.0/8 and your DMZ is 192.168.1.0/24,
> this will prevent traffic from the DMZ to the inside, but allow
> everything else.
>
> PaulM
>
Ok, I think I understand this a little better now. Say my private
network is 192.168.1.0/24 and my dmz is 192.168.2.0/24. I already have
the static (inside,dmz) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
which is required in 6.3(3). So, in order to make this work i.e the
inside network has access to everything on the dmz network and the dmz
network can access the internet and I only allow specific
communication from the dmz to the inside I need to do the following:

access-list dmz permit udp host 192.168.2.2 host 192.168.1.202 eq domain
access-list dmz permit tcp host 192.168.2.2 host 192.168.1.203 eq smtp
access-list dmz deny ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
access-list dmz permit ip 192.168.2.0 255.255.255.0 any

I will also need to add the nonat statements as was suggested by Brandon:

access-list nonat permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
access-list nonat permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
nat 0 (inside) access-list nonat
nat 0 (dmz) access-list nonat

My only concern here is the 3rd line in the dmz access-list and
whether it will deny communication from the inside network to the dmz
(except dns and smtp), but I will test that when I get home tonight.

Thank you for everyone's help.

Brian


------------------------------

Message: 2
Date: Wed, 26 Dec 2007 11:23:14 -0500 (EST)
From: jseymour@linxnet.com (Jim Seymour)
Subject: Re: [fw-wiz] Anyone have any informed opinions on the
Watchguard product line?
To: firewall-wizards@listserv.icsalabs.com
Message-ID: <20071226162314.E4BC9E158@jimsun.linxnet.com>


"Richard Golodner" <rgolodner@infratection.com> wrote:
>
[snip]
> There was also a nice GUI interface ...
[snip]

Is that still limited to running on a Windows PC?

I believe their management GUI once ran on both Windows and Linux.
Then, later, on Windows only, I was told. I tend to shun network
infrastructure products that require Windows to configure and
administer them.

Jim
--
Note: My mail server employs *very* aggressive anti-spam
filtering. If you reply to this email and your email is
rejected, please accept my apologies and let me know via my
web form at <http://jimsun.linxnet.com/contact/scform.php>.


------------------------------

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


End of firewall-wizards Digest, Vol 20, Issue 13
************************************************

Storage Trends Explained

The following message is being sent to you from Network World.

Dear Security,

Storage systems are growing more complex daily. Register for this Webcast, Storage Trends and Options, to hear how new and upcoming trends in storage can benefit your organization.
http://www.accelacomm.com/jlp/EM_80137251_v2121107/7/80137251/

Topics discussed include:

  • ILM (Information Lifecycle Management)
  • Server virtualization
  • Building SANs
  • Role of security
  • Regulatory compliance
  • Litigation readiness
Industry experts explain how IT professionals can prepare for future storage technologies such as ILM, while optimizing current deployments.

Listen to this free Webcast today:
http://www.accelacomm.com/jlp/EM_80137251_v2121107/7/80137251/

Sincerely,
Network World, Inc.

To stop receiving e-mail messages from Network World, do not reply to this e-mail. Instead, please go to our email preference management page at http://www.networkworld.com/nl/pclogin.jsp?email=security.world@gmail.com&code=gateway_wc_622_1227 where you can specify your email preferences and help ensure that we send only the appropriate communications you may be interested in. You may also write to Network World Inc. Attn: ONLINE, 118 Turnpike Road, Southborough, MA 01772.

Read Network World privacy policy http://networkworld.com/tos.html

WindowsNetworking.com - Active Directory Janitor - Voted WindowsNetworking.com Readers’ Choice Award Winner - Administration Tools

WindowsNetworking.com - RealTime Article Update

Hi Security World,

Title: Active Directory Janitor - Voted WindowsNetworking.com Readers' Choice Award Winner - Administration Tools
Author: Site Admin
Link: http://www.WindowsNetworking.com/news/WindowsNetworking-Readers-Choice-Award-Administration-Tools-Active-Directory-Janitor-Nov07.html
Summary: Active Directory Janitor was selected the winner in the Administration Tools category of the WindowsNetworking.com Readers' Choice Awards. DameWare NT Utilities and Total Network Inventory were first runner-up and second runner-up.

Visit the Subscription Management (http://newsletter.isoftmarketing.com/) section to unsubscribe.
WindowsNetworking.com is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@windowsnetworking.com
Copyright © WindowsNetworking.com 2007. All rights reserved.

WindowSecurity.com - Altiris SecurityExpressions - Voted WindowSecurity.com Readers’ Choice Award Winner - Network Auditing Software

Hi Security World,

A new article has been added to WindowSecurity.com:


Title: Altiris SecurityExpressions - Voted WindowSecurity.com Readers' Choice Award Winner - Network Auditing Software
Author: Admin
Link: http://www.WindowSecurity.com/news/WindowSecurity-Readers-Choice-Award-Security-Network-Auditing-Software-Category-AltirisSecurityExpressions-Nov07.html
Summary: Altiris SecurityExpressions was selected the winner in the Network Auditing Software category of the WindowSecurity.com Readers' Choice Awards. Professional Audit Expander and SSL-Explorer Enterprise Edition Protection were first runner-up and second runner-up.

Visit the Subscription Management (http://newsletter.isoftmarketing.com/) section to unsubscribe.
WindowSecurity.com is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@windowsecurity.com
Copyright © WindowSecurity.com 2007. All rights reserved.

ISAserver.org - SurfControl Web Filter Voted ISAserver.org Readers’ Choice Award Winner - Content Security

ISAserver.org - RealTime Article Update

Hi Security World,

Title: SurfControl Web Filter Voted ISAserver.org Readers' Choice Award Winner - Content Security
Author: Site Admin
Link: http://www.ISAserver.org/news/ISAserver-Readers-Choice-Award-Content_Security-SurfControl-Web-Filter-Nov07.html
Summary: SurfControl Web Filter was selected the winner in the Content Security category of the ISAserver.org Readers' Choice awards. GFI WebMonitor and WebSense Enterprise were runner-up and second runner-up respectively.

Visit the Subscription Management (http://newsletter.isoftmarketing.com/) section to unsubscribe.
ISAserver.org is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@isaserver.org

Copyright © ISAserver.org 2007. All rights reserved.

Wednesday, December 26, 2007

About Antivirus Software: Ten Tips to Protect Against Identity Theft

About.com   Antivirus Software
In the Spotlight | More Topics |
  from Mary Landesman


 
In the Spotlight
Ten Tips to Protect Against Identity Theft
Every 3.5 seconds, someone in the U.S. has their identity stolen. This holiday season alone, over 9 million people will be affected. Identity theft is both an online and offline...read more

 
         More Topics
CyberDefender, Elves, and Computer Help
If you're buying or getting a new PC this holiday season, or you've got an older one in need of some TLC, the folks at CyberDefender are giving away a...read more

 
'Tis the Season...for Greeting Card Scams
I received a lovely Bluemountain.com Christmas ecard from an About.com reader. It was touching and delightful. The only downside is that the good greeting card was sandwiched in between several...read more

 
 
Sponsored Links
 
Winter Holidays: Gifts, Decorating Tips, Recipes, and More
Winter Holidays: Gifts, Decorating Tips, Recipes, and More
Ready for the holiday rush? Need help buying the perfect gift for your nephew or planning a fabulous holiday meal? Get expert advice on the best toys, clothes, gadgets and ways to reduce holiday stress.

Advertisement
 
 
Visit Related About GuideSites:
Internet / Network Security Wireless / Networking Focus on Windows
Email Urban Legends and Folklore  
Search About  

 
Sign up for more free newsletters on your favorite topics.

You are receiving this newsletter because you subscribed to the About Antivirus Software newsletter as security.world@GMAIL.COM. If you wish to change or remove your email address, please visit:
http://www.about.com/nl/usgs.htm?nl=antivirus&e=security.world@GMAIL.COM

About respects your privacy. Our Privacy Policy.

Our Contact Information.
249 West 17th Street
New York, NY, 10011

© 2007 About, Inc.

firewall-wizards Digest, Vol 20, Issue 12

Send firewall-wizards mailing list submissions to
firewall-wizards@listserv.icsalabs.com

To subscribe or unsubscribe via the World Wide Web, visit
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
or, via email, send a message with subject or body 'help' to
firewall-wizards-request@listserv.icsalabs.com

You can reach the person managing the list at
firewall-wizards-owner@listserv.icsalabs.com

When replying, please edit your Subject line so it is more specific
than "Re: Contents of firewall-wizards digest..."


Today's Topics:

1. Re: Anyone have any informed opinions on the Watchguard
product line? (Richard Golodner)
2. Re: PIX access-list help (kevin horvath)
3. Re: PIX access-list help (Paul Melson)
4. Re: PIX access-list help (Avishai Wool)


----------------------------------------------------------------------

Message: 1
Date: Mon, 24 Dec 2007 14:08:08 -0500
From: "Richard Golodner" <rgolodner@infratection.com>
Subject: Re: [fw-wiz] Anyone have any informed opinions on the
Watchguard product line?
To: "'Firewall Wizards Security Mailing List'"
<firewall-wizards@listserv.cybertrust.com>
Message-ID: <003501c84660$51f84910$600a0a0a@Antares>
Content-Type: text/plain; charset="us-ascii"

I have had a lot of experience with WG products and was quite
pleased with ease of set up, the ability to control logging and how easy it
was to add deny statements to the box. One of the drawbacks as Paul had
mentioned was the VPN feature set up for site to site and the versions I
have used only allowed up to 100 deny statements. This means a lot of
network aggregation in order to make sure you were not receiving traffic
from places you did not want.
There was also a nice GUI interface that showed in real time who was
attempting to attach to various devices on your network, which mad killing
the spammer attempts much easier. Be sure to do a whois or a trace route
before you include a deny statement since this can cause trouble if you need
transit from the network you just denied. Overall a pretty nice product, but
I still prefer the PIX or some of the other firewall feature sets built into
later versions of the IOS.

most sincerely, Richard

-----Original Message-----
From: firewall-wizards-bounces@listserv.cybertrust.com
[mailto:firewall-wizards-bounces@listserv.cybertrust.com] On Behalf Of Paul
D. Robertson
Sent: Monday, December 24, 2007 11:57 AM
To: Firewall Wizards Security Mailing List
Subject: Re: [fw-wiz] Anyone have any informed opinions on the watchguard
product line?

On Tue, 18 Dec 2007, AMuse wrote:

> Does anyone have an informed opinion on whether these products are any
> good, that I can pass along to my friend?

They work well enough, VPN setup is a little weird if you're doing
site-to-site (at least I ended up dropping back and punting to OpenVPN at
one customer.)

The nice thing is that the HTTP proxy does MIME type filtering, which
stops a lot of junk if you don't open it up wide.

Paul
----------------------------------------------------------------------------
-
Paul D. Robertson "My statements in this message are personal opinions
paul@compuwar.net which may have no basis whatsoever in fact."

http://www.fluiditgroup.com/blog/pdr/

Art: http://PaulDRobertson.imagekind.com/

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


------------------------------

Message: 2
Date: Mon, 24 Dec 2007 16:42:33 -0500
From: "kevin horvath" <kevin.horvath@gmail.com>
Subject: Re: [fw-wiz] PIX access-list help
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID:
<5c41be6e0712241342t15c3bd48x49cf230454d08d1f@mail.gmail.com>
Content-Type: text/plain; charset=UTF-8

if you want access to the internet to from any interface you need to
allow all traffic on the typical ports 80 and 443 and then deny
traffic to internal subnets/hosts that should be denied. The other
way to do this is to do a policy nat on the inside and allow only
traffic you want to be translated and all other traffic will just be
dropped. The latter will cause more cpu to used verse it just being
denied by an access list. Hope this helps. If you need more help
then post a sanitized copy of your acls and translations.

Kevin

On Dec 21, 2007 11:02 AM, Brian Blater <brb.lists@gmail.com> wrote:
> I'm a little befuddled with PIX access lists and need some help and
> understanding. I have a PIX 515 version 6.3(3) with 3 interfaces -
> outside, inside, dmz. Up til now I have only been using the outside
> and inside interface. I have started configuring the dmz interface and
> have set it at security50 (outside = 0, inside = 100). I currently
> have only an access-list on the outside interface allowing some
> specific traffic in to the inside network. Right now the inside and
> dmz can talk to the internet just fine and the inside can talk to the
> dmz network fine. However, I want to implement an access-list on the
> dmz interface and this is where the problems start. If I assign an
> access list to the dmz port to allow smtp from a dmz host to the
> inside mail server I no longer have communication to the internet from
> the dmz and the inside cannot talk to the dmz because of the implicit
> deny of the access list.
>
> So, my main question, is there an access list command I can have that
> basically says "allow all communication from the dmz to the internet"
> and one that says "allow communication from the inside to the dmz"? I
> know I can add "access-list dmz permit ip host 192.168.1.1 any" and
> that solves the problem of getting to the internet, but then it opens
> all communication to the inside from this host and I don't want to do
> that. Since this is version 6.3(3) I can't use an out access-list
> which I think might solve the problem. I have enough memory to run
> version 7.x on this PIX, but I'm trying to tackle one problem at a
> time and I'm a little hesitant about doing the 7.x upgrade just yet.
>
> I have more questions, but I think I start here for now and ask the
> other questions when they are more relevant.
>
> Thanks for your help,
> Brian
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@listserv.icsalabs.com
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>


------------------------------

Message: 3
Date: Tue, 25 Dec 2007 00:25:52 -0500
From: "Paul Melson" <pmelson@gmail.com>
Subject: Re: [fw-wiz] PIX access-list help
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID:
<40ecb01f0712242125i6e1e8aeq33d6e3018c3e3cf1@mail.gmail.com>
Content-Type: text/plain; charset=ISO-8859-1

On Dec 21, 2007 11:02 AM, Brian Blater <brb.lists@gmail.com> wrote:
> So, my main question, is there an access list command I can have that
> basically says "allow all communication from the dmz to the internet"
> and one that says "allow communication from the inside to the dmz"? I
> know I can add "access-list dmz permit ip host 192.168.1.1 any" and
> that solves the problem of getting to the internet, but then it opens
> all communication to the inside from this host and I don't want to do
> that. Since this is version 6.3(3) I can't use an out access-list
> which I think might solve the problem. I have enough memory to run
> version 7.x on this PIX, but I'm trying to tackle one problem at a
> time and I'm a little hesitant about doing the 7.x upgrade just yet.

The short answer to your question is that PIX access-lists are read,
per-interface, top-to-bottom:

access-list dmz_in deny ip 192.168.1.0 255.255.255.0 10.0.0.0 255.0.0.0
access-list dmz_in permit ip 192.168.1.0 255.255.255.0 any
access-group dmz_in in interface dmz

If your internal network is 10.0.0.0/8 and your DMZ is 192.168.1.0/24,
this will prevent traffic from the DMZ to the inside, but allow
everything else.

PaulM


------------------------------

Message: 4
Date: Tue, 25 Dec 2007 00:11:13 +0200
From: "Avishai Wool" <yash@acm.org>
Subject: Re: [fw-wiz] PIX access-list help
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID:
<8a9b1fe30712241411m18dafedene929d4ab3bccd87b@mail.gmail.com>
Content-Type: text/plain; charset=ISO-8859-1

Brian,

You probably also need a "static (inside, dmz)" command to
configure the NAT for traffic from a lower security level (the dmz)
to the higher (== inside). You must have the "static" even if you
don't want to actually change the addresses - in that case
the "translate from" and "translate to" addresses will be the same.
the "static" informs the PIX which inside IP addresses are
at all visible from the dmz side.

I think Cisco removed the requirement to always have a "static" with v7.0
but in v6.3 you still need it.

HTH,
Avishai

On 12/21/07, Brian Blater <brb.lists@gmail.com> wrote:
> I'm a little befuddled with PIX access lists and need some help and
> understanding. I have a PIX 515 version 6.3(3) with 3 interfaces -
> outside, inside, dmz. Up til now I have only been using the outside
> and inside interface. I have started configuring the dmz interface and
> have set it at security50 (outside = 0, inside = 100). I currently
> have only an access-list on the outside interface allowing some
> specific traffic in to the inside network. Right now the inside and
> dmz can talk to the internet just fine and the inside can talk to the
> dmz network fine. However, I want to implement an access-list on the
> dmz interface and this is where the problems start. If I assign an
> access list to the dmz port to allow smtp from a dmz host to the
> inside mail server I no longer have communication to the internet from
> the dmz and the inside cannot talk to the dmz because of the implicit
> deny of the access list.
>
> So, my main question, is there an access list command I can have that
> basically says "allow all communication from the dmz to the internet"
> and one that says "allow communication from the inside to the dmz"? I
> know I can add "access-list dmz permit ip host 192.168.1.1 any" and
> that solves the problem of getting to the internet, but then it opens
> all communication to the inside from this host and I don't want to do
> that. Since this is version 6.3(3) I can't use an out access-list
> which I think might solve the problem. I have enough memory to run
> version 7.x on this PIX, but I'm trying to tackle one problem at a
> time and I'm a little hesitant about doing the 7.x upgrade just yet.
>
> I have more questions, but I think I start here for now and ask the
> other questions when they are more relevant.
>
> Thanks for your help,
> Brian
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@listserv.icsalabs.com
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>


--
Avishai Wool, Ph.D., Co-founder and Chief Technical Officer

http://www.algosec.com
******* Firewall Management Made Smarter ******


------------------------------

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


End of firewall-wizards Digest, Vol 20, Issue 12
************************************************

firewall-wizards Digest, Vol 20, Issue 11

Send firewall-wizards mailing list submissions to
firewall-wizards@listserv.icsalabs.com

To subscribe or unsubscribe via the World Wide Web, visit
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
or, via email, send a message with subject or body 'help' to
firewall-wizards-request@listserv.icsalabs.com

You can reach the person managing the list at
firewall-wizards-owner@listserv.icsalabs.com

When replying, please edit your Subject line so it is more specific
than "Re: Contents of firewall-wizards digest..."


Today's Topics:

1. Re: PIX access-list help (Fetch, Brandon)
2. Re: PIX access-list help (Fetch, Brandon)
3. Re: PIX access-list help (Farrukh Haroon)
4. PIX and access-lists (Mikael Velschow-Rasmussen)


----------------------------------------------------------------------

Message: 1
Date: Tue, 25 Dec 2007 17:13:50 -0500
From: "Fetch, Brandon" <bfetch@tpg.com>
Subject: Re: [fw-wiz] PIX access-list help
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID:
<AA8E89377DCB1C498CF19E343CA49D8E2DB468@NYEXCHSVR01.texpac.com>
Content-Type: text/plain; charset="us-ascii"

Easiest thing to remember is any communication is allowed from a higher
security interface to a lower security one (inside to outside, inside to
DMZ, DMZ to outside) unless explicitly prevented.

Next thing is to remember the application of ACLs is from the physical
interface's perspective.

You create an ACL and apply it either in or out of the interface.

Preventing packets from leaving that network, ie coming "in" to the
interface, are applied "access-group in interface blah".

To prevent packets from entering that network, ie going "out" to that
interface, are applied "access-group out interface blah".

Allowing packets from the Internet to a DMZ host requires two items:
A "static" configuration line mapping for the outside IP & port to the
internal IP & port.
A inbound ACL applied "in" on the outside interface.

In your particular case it sounds like a minor change of your ACL and
the application in the opposite direction on the DMZ interface would fix
the problem.

Some examples:
static (DMZ,outside) tcp 22.22.22.22 http 10.10.10.10 http netmask
255.255.255.255 0 0
static(DMZ, outside) tcp 22.22.22.23 smtp 10.10.10.11 smtp netmask
255.255.255.255 0 0
access-list inbound permit tcp any 22.22.22.22 eq http
access-list inbound permit tcp any 22.22.22.23 eq smtp
access-group inbound in interface outside
(allow web access to 22.22.22.22 & SMTP to .23 from the Internet)

access-list DMZ-to-inside permit tcp host 10.10.10.11 192.168.1.11 eq
smtp
access-group DMZ-to-inside in interface DMZ
(allow SMTP from DMZ-10.10.10.11 to inside-192.168.1.11)

To prevent outbound from the inside network to either Internet or DMZ
you can apply an ACL "out" on the inside interface.

access-list inside-out permit any any eq http
access-list inside-out permit any any eq 443
access-list inside-out permit any 192.168.1.11 eq smtp
access-group inside-out in interface inside
(This will only allow outbound HTTP/S & SMTP to either the Internet or
DMZ)

You can also help lock-down any packet leakage by applying an outbound
ACL to our outside interface to allow only what you want leaving your
network.

Remembering to do both sides of the firewall is a good security practice
overall.

HTH,
Brandon

-----Original Message-----
From: firewall-wizards-bounces@listserv.icsalabs.com
[mailto:firewall-wizards-bounces@listserv.icsalabs.com] On Behalf Of
Brian Blater
Sent: Friday, December 21, 2007 11:02 AM
To: FW Wiz
Subject: [fw-wiz] PIX access-list help

I'm a little befuddled with PIX access lists and need some help and
understanding. I have a PIX 515 version 6.3(3) with 3 interfaces -
outside, inside, dmz. Up til now I have only been using the outside
and inside interface. I have started configuring the dmz interface and
have set it at security50 (outside = 0, inside = 100). I currently
have only an access-list on the outside interface allowing some
specific traffic in to the inside network. Right now the inside and
dmz can talk to the internet just fine and the inside can talk to the
dmz network fine. However, I want to implement an access-list on the
dmz interface and this is where the problems start. If I assign an
access list to the dmz port to allow smtp from a dmz host to the
inside mail server I no longer have communication to the internet from
the dmz and the inside cannot talk to the dmz because of the implicit
deny of the access list.

So, my main question, is there an access list command I can have that
basically says "allow all communication from the dmz to the internet"
and one that says "allow communication from the inside to the dmz"? I
know I can add "access-list dmz permit ip host 192.168.1.1 any" and
that solves the problem of getting to the internet, but then it opens
all communication to the inside from this host and I don't want to do
that. Since this is version 6.3(3) I can't use an out access-list
which I think might solve the problem. I have enough memory to run
version 7.x on this PIX, but I'm trying to tackle one problem at a
time and I'm a little hesitant about doing the 7.x upgrade just yet.

I have more questions, but I think I start here for now and ask the
other questions when they are more relevant.

Thanks for your help,
Brian
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


This message is intended only for the person(s) to which it is addressed
and may contain privileged, confidential and/or insider information.
If you have received this communication in error, please notify us
immediately by replying to the message and deleting it from your computer.
Any disclosure, copying, distribution, or the taking of any action concerning
the contents of this message and any attachment(s) by anyone other
than the named recipient(s) is strictly prohibited.

------------------------------

Message: 2
Date: Tue, 25 Dec 2007 17:16:02 -0500
From: "Fetch, Brandon" <bfetch@tpg.com>
Subject: Re: [fw-wiz] PIX access-list help
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID:
<AA8E89377DCB1C498CF19E343CA49D8E2DB469@NYEXCHSVR01.texpac.com>
Content-Type: text/plain; charset="us-ascii"

Oh - my earlier response presumed to NOT perform any NAT'ing between the
inside & DMZ interfaces.

access-list nonat permit ip 10.10.10.0 255.255.255.0 192.168.1.0
255.255.255.0
access-list nonat permit ip 192.168.1.0 255.255.255.0 10.10.10.0
255.255.255.0
nat 0 (inside) access-list nonat
nat 0 (DMZ) access-list nonat

Sorry for the double response to your question!
Brandon

-----Original Message-----
From: firewall-wizards-bounces@listserv.icsalabs.com
[mailto:firewall-wizards-bounces@listserv.icsalabs.com] On Behalf Of
Brian Blater
Sent: Friday, December 21, 2007 11:02 AM
To: FW Wiz
Subject: [fw-wiz] PIX access-list help

I'm a little befuddled with PIX access lists and need some help and
understanding. I have a PIX 515 version 6.3(3) with 3 interfaces -
outside, inside, dmz. Up til now I have only been using the outside
and inside interface. I have started configuring the dmz interface and
have set it at security50 (outside = 0, inside = 100). I currently
have only an access-list on the outside interface allowing some
specific traffic in to the inside network. Right now the inside and
dmz can talk to the internet just fine and the inside can talk to the
dmz network fine. However, I want to implement an access-list on the
dmz interface and this is where the problems start. If I assign an
access list to the dmz port to allow smtp from a dmz host to the
inside mail server I no longer have communication to the internet from
the dmz and the inside cannot talk to the dmz because of the implicit
deny of the access list.

So, my main question, is there an access list command I can have that
basically says "allow all communication from the dmz to the internet"
and one that says "allow communication from the inside to the dmz"? I
know I can add "access-list dmz permit ip host 192.168.1.1 any" and
that solves the problem of getting to the internet, but then it opens
all communication to the inside from this host and I don't want to do
that. Since this is version 6.3(3) I can't use an out access-list
which I think might solve the problem. I have enough memory to run
version 7.x on this PIX, but I'm trying to tackle one problem at a
time and I'm a little hesitant about doing the 7.x upgrade just yet.

I have more questions, but I think I start here for now and ask the
other questions when they are more relevant.

Thanks for your help,
Brian
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


This message is intended only for the person(s) to which it is addressed
and may contain privileged, confidential and/or insider information.
If you have received this communication in error, please notify us
immediately by replying to the message and deleting it from your computer.
Any disclosure, copying, distribution, or the taking of any action concerning
the contents of this message and any attachment(s) by anyone other
than the named recipient(s) is strictly prohibited.

------------------------------

Message: 3
Date: Tue, 25 Dec 2007 02:20:22 +0300
From: "Farrukh Haroon" <farrukhharoon@gmail.com>
Subject: Re: [fw-wiz] PIX access-list help
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID:
<eff3217d0712241520t2a35fbg73064b4cd9d69a56@mail.gmail.com>
Content-Type: text/plain; charset="iso-8859-1"

Brian, as you stated in version 6.x you cannot have outbound ACLs.

"allow all communication from the dmz to the internet"

This can be done by the ACL you suggested:

access-list dmz permit ip <dmz-subnet> <dmz-subnet-mask><http://192.168.1.1/>any

If you don't want certain or all DMZ hosts to initiate traffic to the
inside, you can add some deny ACLs on top of the above access-list, the
access-list is processed in the order you define 'em. The 'show access-list'
command would should you these line numbers E.g. the beloe ACL denies DMZ
host 192.168.1.1 from going to the inside host 10.10.10.10. But it can go
everywhere else...

access-list dmz line 1 extended deny ip host 192.168.1.1 host 10.10.10.10
access-list dmz line 2 extended permit ip host 192.168.1.1 any

Regarding you statement:

"inside cannot talk to the dmz because of the implicit
deny of the access list."

I really don't think this is true :). Which implicit deny are you talking
about here? You never applied an access-list on the inside interface. Lets
says inside user 10.10.10.5 wants to speak to DMZ host 192.168.1.5, what
really is required?

> At least a dynamic NAT (since its version 6.x and there is nat-control).
Static NAT, identity NAT etc. would also work....

> Since its Higher to Lower, there is Default Implicit Permit.

All traffic that the firewall can 'inspect' will be allowed back by virtue
of the state table (the DMZ ACL would not be check here sine this would be
'returning traffic' ).....However if you are running a protocol that uses
'embedding' to hide IP/Ports etc. (like most MultiMedia apps) or you are
using a protocol like FTP/TFTP/XDMCP that does not behave in a symmetric
manner (in terms of flows), you need to firewall to do 'fixup' for that
particular protocol. If you were using normal pings to check, just make sure
you are inspecting icmp 'fixup protocol icmp'.

Regards

Farrukh

On Dec 21, 2007 7:02 PM, Brian Blater <brb.lists@gmail.com> wrote:

> I'm a little befuddled with PIX access lists and need some help and
> understanding. I have a PIX 515 version 6.3(3) with 3 interfaces -
> outside, inside, dmz. Up til now I have only been using the outside
> and inside interface. I have started configuring the dmz interface and
> have set it at security50 (outside = 0, inside = 100). I currently
> have only an access-list on the outside interface allowing some
> specific traffic in to the inside network. Right now the inside and
> dmz can talk to the internet just fine and the inside can talk to the
> dmz network fine. However, I want to implement an access-list on the
> dmz interface and this is where the problems start. If I assign an
> access list to the dmz port to allow smtp from a dmz host to the
> inside mail server I no longer have communication to the internet from
> the dmz and the inside cannot talk to the dmz because of the implicit
> deny of the access list.
>
> So, my main question, is there an access list command I can have that
> basically says "allow all communication from the dmz to the internet"
> and one that says "allow communication from the inside to the dmz"? I
> know I can add "access-list dmz permit ip host 192.168.1.1 any" and
> that solves the problem of getting to the internet, but then it opens
> all communication to the inside from this host and I don't want to do
> that. Since this is version 6.3(3) I can't use an out access-list
> which I think might solve the problem. I have enough memory to run
> version 7.x on this PIX, but I'm trying to tackle one problem at a
> time and I'm a little hesitant about doing the 7.x upgrade just yet.
>
> I have more questions, but I think I start here for now and ask the
> other questions when they are more relevant.
>
> Thanks for your help,
> Brian
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@listserv.icsalabs.com
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: https://listserv.icsalabs.com/pipermail/firewall-wizards/attachments/20071225/ce6a8f48/attachment-0001.html


------------------------------

Message: 4
Date: Wed, 26 Dec 2007 10:59:33 +0100
From: "Mikael Velschow-Rasmussen" <mvr@nworks.dk>
Subject: [fw-wiz] PIX and access-lists
To: <firewall-wizards@listserv.icsalabs.com>, <brb.lists@gmail.com>
Message-ID:
<BF2754820AFAC34EAA01B7BA21FF89CD0B17A6@aragorn.nworks.local>
Content-Type: text/plain; charset="us-ascii"

Brian wrote:
>...
>So, my main question, is there an access list command I can have that
basically says "allow all communication from >the dmz to the internet"
and one that says "allow communication from the inside to the dmz"? I
know I can add >"access-list dmz permit ip host 192.168.1.1 any" and
that solves the problem of getting to the internet, but then it >opens
all communication to the inside from this host and I don't want to do
that. Since this is version 6.3(3) I >can't use an out access-list which
I think might solve the problem. I have enough memory to run version 7.x
on this >PIX, but I'm trying to tackle one problem at a time and I'm a
little hesitant about doing the 7.x upgrade just yet.
>...

Before Cisco PIX used access-lists they implemented the following model:
- security level defines from which interface to which interface
traffic is allowed to initiate. (i.e. all traffic from inside to outside
is permitted, and all traffic from outside to inside is denied).
- if you wanted traffic from low to high security level to be initiated
(i.e. permitted) you would have to use conduit statements (conduit
command plus static command typically, to e.g. allow incoming mail
traffic).
- example:
static (inside,outside) public-outside-ip inside-private-ip
conduit permit tcp host public-outside-ip eq smtp any
- if you wanted to deny traffic from low to high (default was - as seen
above - to permit anything) you needed to use the outbound and apply
commands.

I guess Cisco wanted to bring the IOS command syntax and the PIX syntax
closer together. So they implemented access-list commands in the PIX.
(there is also more flexibility/features in the acl command structure)

With the use of access-lists the need for security levels actually
disappear. If you need to implement acl's that complies to the security
level model described above just use the following:
access-group outside-acl in interface outside
access-group inside-acl in interface inside
access-list outside-acl deny ip any any
access-list inside-acl permit ip any any
These 4 lines accomplishes the same as the security level commands in
'old' PIX language.
(but I guess Cisco just kept the security level in to ensure that
customers not inadvertently opened up the the whole Internet to the
inside network)

So back to your case !
The following list on your dmz should suffice:
access-group dmz-acl in interface dmz
access-list dmz-acl permit tcp host dmz-host-ip private-lan-ip/24 eq
smtp
access-list dmz-acl deny ip any private-lan-ip/24
access-list dmz-acl permit ip any any
(note: It's assumed that the private LAN is a /24 subnet. And that there
is no NAT between inside and DMZ (i.e. NAT0 rule))
You shouldn't need to change anything under the inside or outside
interface since you're already using the above mentioned 4 lines
implicitly through the use of security levels.

Regards
Mikael Velschow-Rasmussen
M.Sc.e.e., CCIE #9973, CCSI #22493,
INFOSEC, SANS GCFW #0565, HP MASE
mvr@nworks.dk


------------------------------

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


End of firewall-wizards Digest, Vol 20, Issue 11
************************************************

Oiee, lembra de mim? Anexei nossas fotos

Oie!!

tudo bem? eu esqueci de mandar as fotos! agora tá ai!!

Beijao!

anexo: photos.gif (15kb)

[SECURITY] [DSA 1437-1] New cupsys packages fix several vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1437-1 security@debian.org
http://www.debian.org/security/

Moritz Muehlenhoff
December 26, 2007

http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package : cupsys
Vulnerability : several
Problem type : local
Debian-specific: no
CVE Id(s) : CVE-2007-5849 CVE-2007-6358

Several local vulnerabilities have been discovered in the Common UNIX
Printing System. The Common Vulnerabilities and Exposures project
identifies the following problems:

CVE-2007-5849

Wei Wang discovered that an buffer overflow in the SNMP backend
may lead to the execution of arbitrary code.

CVE-2007-6358

Elias Pipping discovered that insecure handling of a temporary
file in the pdftops.pl script may lead to local denial of service.
This vulnerability is not exploitable in the default configuration.

For the stable distribution (etch), these problems have been fixed in
version 1.2.7-4etch2.

The old stable distribution (sarge) is not affected by CVE-2007-5849.
The other issue doesn't warrant an update on it's own and has been
postponed.

For the unstable distribution (sid), these problems have been fixed in
version 1.3.5-1.

We recommend that you upgrade your cupsys packages.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian 4.0 (stable)
- -------------------

Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2.dsc

Size/MD5 checksum: 1084 7eda7d3797d141d174e163f837cd91b4

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7.orig.tar.gz

Size/MD5 checksum: 4214272 c9ba33356e5bb93efbcf77b6e142e498

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2.diff.gz

Size/MD5 checksum: 103089 a856a1ff975042783cb87f23d15e5b3a

Architecture independent packages:

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-gnutls10_1.2.7-4etch2_all.deb

Size/MD5 checksum: 45246 3216cd80859aa97b7c8c5774b2462db2

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-common_1.2.7-4etch2_all.deb

Size/MD5 checksum: 893020 28b90e7e58400b9216f72cecf7de0d4a

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_alpha.deb

Size/MD5 checksum: 1096542 686386cd43230708d49cea4af0d57b9f

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_alpha.deb

Size/MD5 checksum: 94468 32d1efdef788039ac00ed1e57a6fcc47

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_alpha.deb

Size/MD5 checksum: 1608840 d042363f0999e1f11939e3f5e8de8b38

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_alpha.deb

Size/MD5 checksum: 72432 5e43d1208715258c4ff09dcee0fa4081

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_alpha.deb

Size/MD5 checksum: 86284 dca9ccc53cb8fcf7b8e1a44b8e76a6ad

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_alpha.deb

Size/MD5 checksum: 184372 cb6c4f2c2a08ccc55c25c35d039fe400

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_alpha.deb

Size/MD5 checksum: 39260 cdfc7a39f71c1aed6973a2956cf8749d

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_alpha.deb

Size/MD5 checksum: 174608 e2c1ebf86bfc9f538a640c8ea385330f

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_amd64.deb

Size/MD5 checksum: 142552 60167bc344afbaa54904b295c78def9c

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_amd64.deb

Size/MD5 checksum: 36366 3feca5f614aca7d527b1beba01462f6e

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_amd64.deb

Size/MD5 checksum: 161666 65ebf0f70d842eeb8adc309946357b4d

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_amd64.deb

Size/MD5 checksum: 85314 0be1f821b4880c7a4b83cd7779edbce4

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_amd64.deb

Size/MD5 checksum: 80704 26db3ea2f4aee728ead9ffba2686b827

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_amd64.deb

Size/MD5 checksum: 1574360 3a1e7f5f6a8766a1f89aa65fc47c5d72

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_amd64.deb

Size/MD5 checksum: 52862 3e8caecdc231fcded29f0029b76019a8

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_amd64.deb

Size/MD5 checksum: 1085694 235f96f3c07947ab11cd4222490441f0

arm architecture (ARM)

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_arm.deb

Size/MD5 checksum: 48532 08ce8a9c2d9edf30a381ddc34073c397

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_arm.deb

Size/MD5 checksum: 1025036 c3165815ab4292c0b200176c4c0ad7d6

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_arm.deb

Size/MD5 checksum: 35924 02c6ebde8deb0fcb39074deb5895b95b

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_arm.deb

Size/MD5 checksum: 78912 33627a4c4e1dd3b4001f165cfda64259

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_arm.deb

Size/MD5 checksum: 132054 c4e04d8fb763e599931f3cb0207d84cb

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_arm.deb

Size/MD5 checksum: 154314 0dcbd01293a5a0925af776bc0d6490fa

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_arm.deb

Size/MD5 checksum: 84494 66ff0b8a8b07d0faddee758806e044be

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_arm.deb

Size/MD5 checksum: 1568356 725c88c2ac3737a0a323e82a5877f8f9

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_hppa.deb

Size/MD5 checksum: 39264 528456372ac16c6dc257d2672a24cc84

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_hppa.deb

Size/MD5 checksum: 85260 60da86a4e6b72d49f3c405cda6eaaa33

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_hppa.deb

Size/MD5 checksum: 90316 7d7093a9bca7c6ee4a190eaea715cf1f

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_hppa.deb

Size/MD5 checksum: 57026 7e78c5bf532b9761b6ebc290c4c24b94

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_hppa.deb

Size/MD5 checksum: 171548 37bfd1849d459be20f5df6da4d0e8f19

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_hppa.deb

Size/MD5 checksum: 1611932 3a3e91d8c878c6ec42a99d1bfacbafac

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_hppa.deb

Size/MD5 checksum: 154600 fc87ba725d54223245d9cb71777307a7

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_hppa.deb

Size/MD5 checksum: 1031728 cdcfb63a3a2200f4ca36aa0d530c32d9

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_i386.deb

Size/MD5 checksum: 53068 e28d98e95a5e543991b996e84d028863

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_i386.deb

Size/MD5 checksum: 138280 28df76637f6b23d98ec81f6a7bf2b6ba

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_i386.deb

Size/MD5 checksum: 159796 fa2db05d879ce293041be45683febe8b

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_i386.deb

Size/MD5 checksum: 1547840 6d7396410919ae7207d3d9aadfb5026f

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_i386.deb

Size/MD5 checksum: 79880 c392020f91e2901d4122ef6a1fa08fed

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_i386.deb

Size/MD5 checksum: 85778 a11291b1a834d42ba160fb8d92db0c3a

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_i386.deb

Size/MD5 checksum: 997490 0d91574ed291678037351dd0a32f445f

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_i386.deb

Size/MD5 checksum: 36476 ee84ce1774c646915ba410dadcda3470

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_ia64.deb

Size/MD5 checksum: 1107194 dc683bec9dcfffc4a1e020b2859e1fab

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_ia64.deb

Size/MD5 checksum: 106228 db41cfc57bf2d43da703285f9790344c

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_ia64.deb

Size/MD5 checksum: 46332 f52d7a07c6acf6613da1ae43f64b8ef7

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_ia64.deb

Size/MD5 checksum: 203378 9da06426a99702d4485b528d542b666d

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_ia64.deb

Size/MD5 checksum: 105872 cd243300f6b804b2501e5681401c574e

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_ia64.deb

Size/MD5 checksum: 73934 b3618bd2d5b1de8371ea56301312ef3a

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_ia64.deb

Size/MD5 checksum: 192368 35aba3be08e6a72b54617bb666b12d4c

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_ia64.deb

Size/MD5 checksum: 1769808 8d0ab1028149cabd9d946c44cf4d4f86

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_mips.deb

Size/MD5 checksum: 77158 5302b4e5edb3d0d7733481eaabdbddcf

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_mips.deb

Size/MD5 checksum: 85874 d6beacabf8db05137b4c4357ea7557e9

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_mips.deb

Size/MD5 checksum: 157884 d0f4ed5d1da24041179f9f2697f2ffcb

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_mips.deb

Size/MD5 checksum: 1096124 feea35b2ae01af3b06ee3ce8a854324e

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_mips.deb

Size/MD5 checksum: 35968 0bb0b6c1018c466326b6406de4af093e

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_mips.deb

Size/MD5 checksum: 150766 ff55f24b0b36722265644252857d8b5c

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_mips.deb

Size/MD5 checksum: 1550792 97167182293fc8400cb9fefffc3670e7

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_mips.deb

Size/MD5 checksum: 57384 b2473f40bde45105c0bdec916ff93cdb

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_mipsel.deb

Size/MD5 checksum: 86054 f78f586a8f15727e28c67bca58caaa26

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_mipsel.deb

Size/MD5 checksum: 1552410 94190014545b85b403a21e97d9901776

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_mipsel.deb

Size/MD5 checksum: 157716 e0bd0f1e90b1124b1441bc1f313a7764

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_mipsel.deb

Size/MD5 checksum: 1083814 a5968478d72e11f19d4e019d3095e51f

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_mipsel.deb

Size/MD5 checksum: 36068 363ff5b0694c2fef407a92dea1ba1c4e

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_mipsel.deb

Size/MD5 checksum: 77458 db7144590602bf3cf25cba5fdce485a8

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_mipsel.deb

Size/MD5 checksum: 57700 04626a4cb44728ea61bcb7f8d8ddc1ed

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_mipsel.deb

Size/MD5 checksum: 150902 f3cb4f6ca36503d7b70aab6d559199d2

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_powerpc.deb

Size/MD5 checksum: 51792 e89680c8a9b4851ebb5ad0d304e6bbb7

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_powerpc.deb

Size/MD5 checksum: 90002 ce367709844a87951f810524aadfea4c

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_powerpc.deb

Size/MD5 checksum: 136864 0aabc007ab84b86a77f6c601ba8d44fd

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_powerpc.deb

Size/MD5 checksum: 87576 f18bba76c873a6238e78a80182c0cd38

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_powerpc.deb

Size/MD5 checksum: 1575144 506c85d9a8b03be737ccb8dd3fd31248

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_powerpc.deb

Size/MD5 checksum: 1141712 b6ab866de7c8c6f2051c2a813003a722

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_powerpc.deb

Size/MD5 checksum: 162358 08096969b7e8ef48d2ece9a86600004a

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_powerpc.deb

Size/MD5 checksum: 41290 b7eb0528a3b1b8bd07247fd9e16b76c2

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_s390.deb

Size/MD5 checksum: 1586292 01001ec68f5ff6a090ebff3099265be0

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_s390.deb

Size/MD5 checksum: 1035680 081c5ca040751dc4ec59d2a83289099c

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_s390.deb

Size/MD5 checksum: 86854 5011337fee7f4dcfb62a6c95f7054e98

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_s390.deb

Size/MD5 checksum: 37422 731fb2009fa3cf47e270c35348d2e3e4

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_s390.deb

Size/MD5 checksum: 82338 4f93e2f975642addd238eecf78a94779

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_s390.deb

Size/MD5 checksum: 165816 c69411004d08763f1b86a5d517592fc7

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_s390.deb

Size/MD5 checksum: 144946 74bca185776b08ac50a9abcc17019e68

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_s390.deb

Size/MD5 checksum: 52260 1324db10b3374beb81b98032ba92e2b8

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2-dev_1.2.7-4etch2_sparc.deb

Size/MD5 checksum: 51580 6052b09bd8c4cb9600156b24f185122a

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2-dev_1.2.7-4etch2_sparc.deb

Size/MD5 checksum: 139570 2aa5b4d2d64849aa048489332f7e3aca

http://security.debian.org/pool/updates/main/c/cupsys/cupsys_1.2.7-4etch2_sparc.deb

Size/MD5 checksum: 1561428 59199c965cba64d0aaf9a2de6c3432b6

http://security.debian.org/pool/updates/main/c/cupsys/libcupsimage2_1.2.7-4etch2_sparc.deb

Size/MD5 checksum: 84282 edec6a1d4af9df91f2d2b5c20553dbe9

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-dbg_1.2.7-4etch2_sparc.deb

Size/MD5 checksum: 990474 e276a14d21a6d7661c91c3420c96e142

http://security.debian.org/pool/updates/main/c/cupsys/libcupsys2_1.2.7-4etch2_sparc.deb

Size/MD5 checksum: 158256 d43c9657a710bb5969e704208502f59f

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-client_1.2.7-4etch2_sparc.deb

Size/MD5 checksum: 78514 32c106b3332c95dd0f24d6cf5d208add

http://security.debian.org/pool/updates/main/c/cupsys/cupsys-bsd_1.2.7-4etch2_sparc.deb

Size/MD5 checksum: 36020 751c12e8f83f04b5fd54d4a23abdf6fc


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHclSzXm3vHE4uyloRAqN4AJ446Cy9X2qGSIJqCKirOI2pWmEseACgygi1
mLr61xygMrJtafqG+L6vzQw=
=Kaoc
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org