LWN.net Logo

Tawie Server Linux

From:  Tawie Security Advisor <tsl-AT-tawie.org>
To:  tsl-announce-AT-tawie.org
Subject:  TSL-2003-0002 - multi
Date:  Thu, 2 Oct 2003 16:42:07 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Tawie Server Linux Bugfix Advisory #2003-0002

Package name:      proftpd, rsync, rpm, release, swup/swupconf
Summary:           Minor bugfix
Date:              2003-10-02
Affected versions: TSL 1.2, 1.5, 2.0

- --------------------------------------------------------------------------
Package description:
  ProFTPd is an enhanced FTP server with a focus toward simplicity, security,
  and ease of configuration. It features a very Apache-like configuration
  syntax, and a highly customizable server infrastructure, including support
  for multiple 'virtual' FTP servers, anonymous FTP, and permission-based
  directory visibility.

  Rsync uses a quick and reliable algorithm to very quickly bring remote and
  host files into sync. Rsync is fast because it just sends the differences in
  the files over the network (instead of sending the complete files). Rsync is
  often used as a very powerful mirroring process or just as a more capable
  replacement for the rcp command. A technical report which describes the rsync
  algorithm is included in this package.Install rsync if you need a powerful
  mirroring program.

  The RPM Package Manager is a powerful command line driven package
  management system capable of installing, uninstalling, verifying,
  querying, and updating software packages.  Each software package
  consists of an archive of files along with information about the
  package like its version, a description, etc.
  
  Release is a package just to identify the release of the distribution.

  SWUP - SoftWare UPdater is an extension for existing software packaging
  systems to facilitate automatic and secure update and install. SWUP handles
  dependencies between software packages, and is able to fetch additional
  required software when installing or upgrading.  Problem description:
  
Problem description:
  The latest proftpd updates for TSL 1.X where based on the specification for
  TSL 2.0, and didn't work.
  
  In addition the version of rsync shipped in 1.X contained a problem which 
  made partial downloading of files not work as expected.
  The latest rpm update for tawie-2.0 had wrong macros files.

  These upgrades adress the issues.

Action:
  We recommend that all systems with this package installed be upgraded.
  Please note that if you do not need the functionality provided by this
  package, you may want to remove it from your system.


Location:
  All TSL updates are available from
  <URI:http://http.tawie.org/pub/tawie/updates/>
  <URI:ftp://ftp.tawie.org/pub/tawie/updates/>


About Tawie Server Linux:
  Tawie Server Linux is a small Linux distribution for servers. With focus
  on security and stability, the system is painlessly kept safe and up to
  date from day one using swup, the automated software updater.


Automatic updates:
  Users of the SWUP tool can enjoy having updates automatically
  installed using 'swup --upgrade'.


Public testing:
  These packages have been available for public testing for some time.
  If you want to contribute by testing the various packages in the
  testing tree, please feel free to share your findings on the
  tsl-discuss mailinglist.
  The testing tree is located at
  <URI:http://tsldev.tawie.org/cloud/>

  You may also use swup for public testing of updates:
  
  site {
      class = 0
      location = "http://tsldev.tawie.org/cloud/rdfs/latest.rdf"
      regexp = ".*"
  }
  

Questions?
  Check out our mailing lists:
  <URI:http://www.tawie.net/support/>


Verification:
  This advisory along with all TSL packages are signed with the TSL sign key.
  This key is available from:
  <URI:http://www.tawie.net/TSL-SIGN-KEY>

  The advisory itself is available from the errata pages at
  <URI:http://www.tawie.net/errata/tawie-1.2/>,
  <URI:http://www.tawie.net/errata/tawie-1.5/> and
  <URI:http://www.tawie.net/errata/tawie-2.0/>
  or directly at
  <URI:http://www.tawie.net/errata/misc/tawie-2003/TSL-2003-0002-multi.asc.txt>


MD5sums of the packages:
- --------------------------------------------------------------------------
d880bf84111498d99282d142c04662d5  ./2.0/SRPMS/swupconf-2.0-4tsl.src.rpm
6fba9a01e227b2e1bfc78247116e00ef  ./2.0/SRPMS/rsync-2.5.6-1tsl.src.rpm
a92c02ca90c6a7c121f3aab54fd561b6  ./2.0/SRPMS/rpm-4.0.4-20tsl.src.rpm
b3e28a3122e19b9925a93687a27b7b8c  ./2.0/RPMS/swupconf-2.0-4tsl.noarch.rpm
22c3711b4af30cbdfeb655290c54a204  ./2.0/RPMS/rsync-server-2.5.6-1tsl.i586.rpm
4db7d60cfa364b7e5ec0df86992b74b9  ./2.0/RPMS/rsync-2.5.6-1tsl.i586.rpm
4205f8ec1cafe46f53153fd6c6873463  ./2.0/RPMS/rpm-python-4.0.4-20tsl.i586.rpm
8d4a16ea55819c70d80f711300c66118  ./2.0/RPMS/rpm-perl-4.0.4-20tsl.i586.rpm
4ab8500b754060bbf78b53c371f88095  ./2.0/RPMS/rpm-devel-4.0.4-20tsl.i586.rpm
ebcc447a8764b7b210a9de657282bbe1  ./2.0/RPMS/rpm-build-4.0.4-20tsl.i586.rpm
784f6bdc44f826b60a32cb31a1029d4c  ./2.0/RPMS/rpm-4.0.4-20tsl.i586.rpm
a511585ea54518c6c1d211748241860c  ./1.5/SRPMS/swup-0.1.7-6tr.src.rpm
2d112c1597bdd8012ccc01f65eb31335  ./1.5/SRPMS/release-1.5-2tr.src.rpm
e19680617664c739ec8c33aef158e3e2  ./1.5/SRPMS/proftpd-1.2.8-11tr.src.rpm
5bb6a6abf6b9ebd67fb3f97e9119137e  ./1.5/RPMS/swup-0.1.7-6tr.noarch.rpm
5e1dc0502b98f5b7eb1dba2f57d278c9  ./1.5/RPMS/rsync-2.5.6-1tr.i586.rpm
386730b541fdc93b315712dddc0a719a  ./1.5/RPMS/release-1.5-2tr.noarch.rpm
35480db12b46d0e0f2f1731796c40c4a  ./1.5/RPMS/proftpd-1.2.8-11tr.i586.rpm
5f196b7a6aabfe9719fa96e0755c01f3  ./1.2/SRPMS/swup-0.0.8-4tr.src.rpm
32842c718ee727bb27f505d196f002cc  ./1.2/SRPMS/rsync-2.5.6-1tr.src.rpm
5a7d2b5bcaeea84011e0eb4d20615d24  ./1.2/SRPMS/release-1.2-2tr.src.rpm
29f59c16b78527cdca66eb060a6c12e2  ./1.2/SRPMS/proftpd-1.2.8-11tr.src.rpm
ef584f38ffc10a8dfe1e52f7a8be716b  ./1.2/RPMS/swup-0.0.8-4tr.noarch.rpm
7aa7772f81884660711bda055f33312c  ./1.2/RPMS/rsync-2.5.6-1tr.i586.rpm
0c8e4a9ffe9dabb5e6123c7007d6cf0e  ./1.2/RPMS/release-1.2-2tr.noarch.rpm
b5b658ebd2ff2c52990e4026163bb9a3  ./1.2/RPMS/proftpd-1.2.8-11tr.i586.rpm
- --------------------------------------------------------------------------


Tawie Security Team

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQE/fDSou9Q/LWRYgjERAiBQAJ9PvBsHXwGzLsWSmhBqBKWF+pg2fgCffTYZ
cjbfzEpr1c/koDFVSqGQUrk=
=6Ia+
-----END PGP SIGNATURE-----

_______________________________________________
tsl-announce mailing list
tsl-announce-AT-tawie.org
http://www.tawie.org/mailman/listinfo/tsl-announce


(Log in to post comments)

Copyright © 2003, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds