Weblog entry #12 for oxtan

debian security
Posted by oxtan on Mon 14 May 2007 at 17:21
Tags: none.
on May 13th I got 2 emails from the debian-security list warning me about 2 patches, one for squirrelmail and one for the kernel.

I have repeatedly run apt-get update && apt-get upgrade, but nothing is happening.

my sources.list is:

deb http://security.debian.org/ etch/updates main
deb-src http://security.debian.org/ etch/updates main contrib
deb http://ftp.de.debian.org/debian etch main

Has anybody had this problem?

 

Comments on this Entry

Posted by Anonymous (86.12.xx.xx) on Mon 14 May 2007 at 19:52
what does dpkg say the current version of squirrelmail is installed?
type "dpkg -l |grep squirrelmail" to get the version, the fixed version is 1.4.9a-2 in etch. thats L lowercase.

http://www.debian.org/security/2007/dsa-1290

maybe you already have the update :)

sno

[ Parent | Reply to this comment ]

Posted by oxtan (82.95.xx.xx) on Mon 14 May 2007 at 19:55
[ Send Message | View Weblogs ]
before posting my question I had already checked the installed versions. Sorry for not pointing this out.

no, my version is not patched

[ Parent | Reply to this comment ]

Posted by Anonymous (86.12.xx.xx) on Mon 14 May 2007 at 20:01
sorry forgot to mention kernel information, the kernel doesn't get upgraded automatically with apt-get upgrade or apt-get dist-upgrade, you need to apt-get install linux-image-xxx , for me its linux-image-k7, so replace with whichever arch you are using. This installs installs the latest (ie updated/fixed) kernel and downloads from security.debian.org.

hope this helps

sno

[ Parent | Reply to this comment ]

Posted by oxtan (82.95.xx.xx) on Mon 14 May 2007 at 20:26
[ Send Message | View Weblogs ]
no, that does not work either. I remember a couple of weeks ago there was also an update for the kernel. I could install it then with the usual apt-get mantra.

[ Parent | Reply to this comment ]

Posted by JulienV (90.6.xx.xx) on Tue 15 May 2007 at 18:08
[ Send Message | View Weblogs ]
I had the very same issue with 2 servers, whereas 2 other servers were upgraded without problems (using the same DNS server).

I have been told on the debian-user-french mailing list that one the 3 machines hosting security.d.o has had disk capacity problem. But I am not sure this explains the problem, as security.d.o has 3 IPs, and the DNS takes one at random, thus with the numerous tests I have made, I think I should have hit one of the updated servers...
With Firefox, all my tests were successful (testing the /pool directory and the Packages.bz2 file).

Several French users reported the same issue.

Cheers,
Julien

[ Parent | Reply to this comment ]

Posted by Alucard (24.91.xx.xx) on Tue 15 May 2007 at 04:23
[ Send Message | View Weblogs ]
I had the same problem on only one of my servers, but I just did and update and upgrade and it finally saw the upgrade.

[ Parent | Reply to this comment ]

Posted by oxtan (82.95.xx.xx) on Tue 15 May 2007 at 06:10
[ Send Message | View Weblogs ]
yes, now I was indeed able to update it.

I wonder why they publish the vulnerabilities if one cannot patch the systems straight ahead. Maybe the security repository is replicated across different servers in different countries and the replication has not worked properly this time.

[ Parent | Reply to this comment ]

Posted by Anonymous (213.94.xx.xx) on Wed 16 May 2007 at 10:50
Err http://security.debian.org sarge/updates/main Packages
Could not connect to security.debian.org:80 (212.211.132.32), connection timed out [IP: 212.211.132.32 80]
Err http://security.debian.org sarge/updates/main Release
Could not connect to security.debian.org:80 (212.211.132.32), connection timed out [IP: 212.211.132.32 80]
Err http://security.debian.org sarge/updates/non-free Packages
Could not connect to security.debian.org:80 (212.211.132.32), connection timed out [IP: 212.211.132.250 80]


Hi,

Seem to be having the same problem here! Anyone know if there's a general issue?

cheers.
Murf.

[ Parent | Reply to this comment ]

Posted by Anonymous (213.94.xx.xx) on Thu 17 May 2007 at 15:58
Never mind the above, seems there's a routing issue with our upstream ISP.

cheers,
Murf.

[ Parent | Reply to this comment ]

User Login

Username:

Password:

[ Advanced Login ]

Register Account

Quick Site Search