Email address obfuscation in effect -- please
click here to turn it off.
[
Date Prev][
Date Next][
Thread Prev][
Thread Next][
Date Index][
Thread Index]
- To: "MLUG Members" <EMAIL:PROTECTED>
- Subject: Re: [MLUG] MLUG admins: Squirrelmail server.
- From: "Mark Rages" <EMAIL:PROTECTED>
- Date: Tue, 16 Jan 2007 17:26:57 -0600
- Delivery-date: Tue, 16 Jan 2007 17:27:19 -0600
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=HCHPUGV84flUbdqy8CuB06norWjv2jyPUhTKnCpR02oX5Vfs7LMj4BkNq3lTh35uWqkzOn6nKRNkuddozI0GxzLIQazZjbkagHJUXMafTuINobZDXVqvlOf4L3FZl98FnmHPbxF1318gSUHkchhBxpEooliBsdAjWxmF/okmUP0=
- Envelope-to: EMAIL:PROTECTED
- In-reply-to: <EMAIL:PROTECTED>
- References: <EMAIL:PROTECTED> <EMAIL:PROTECTED>
- Reply-to: MLUG Members <EMAIL:PROTECTED>
- Sender: EMAIL:PROTECTED
On 1/16/07, Jerry Gamblin <EMAIL:PROTECTED> wrote:
On 1/16/07, Mark Rages <EMAIL:PROTECTED> wrote:
> I annoyed somebody on another list and he made [what could be
> interpreted as] a vague threat about the Squirrelmail installation on
> MLUG.
>
> Here's the post:
> http://article.gmane.org/gmane.comp.hardware.microcontrollers.pic/107371
1.4.6 does have known issues:
http://www.securityfocus.com/bid/21414
We should be on 1.4.9, but I don't even know who is in charge of
updating server.
On the other hand making threats against an educational server isnt very smart.
Doesn't Debian backport security patches? So just going by version
numbers won't tell if the vulnerability is there. I ran into this at
my last job, when a security consultant made a scary report about
vulnerable software, by just checking version numbers.
Regards,
Mark
EMAIL:PROTECTED
--
You think that it is a secret, but it never has been one.
- fortune cookie
_______________________________________________
members mailing list
EMAIL:PROTECTED
http://mlug.missouri.edu/mailman/listinfo/members