Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #191444 > unrolled thread

Question on CVE-2017-5754 on Debian 8.9

Started byNicholas Geovanis <nickgeovanis@gmail.com>
First post2018-01-23 22:10 +0100
Last post2018-01-25 23:40 +0100
Articles 4 on this page of 64 — 14 participants

Back to article view | Back to linux.debian.user


Contents

  Question on CVE-2017-5754 on Debian 8.9 Nicholas Geovanis <nickgeovanis@gmail.com> - 2018-01-23 22:10 +0100
    Re: Question on CVE-2017-5754 on Debian 8.9 Sven Hartge <sven@svenhartge.de> - 2018-01-23 22:20 +0100
      Re: Question on CVE-2017-5754 on Debian 8.9 Nicholas Geovanis <nickgeovanis@gmail.com> - 2018-01-23 22:40 +0100
        Re: Question on CVE-2017-5754 on Debian 8.9 Sven Hartge <sven@svenhartge.de> - 2018-01-23 22:40 +0100
      Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-23 23:10 +0100
        Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-23 23:50 +0100
          Re: Question on CVE-2017-5754 on Debian 8.9 Richard Hector <richard@walnut.gen.nz> - 2018-01-24 00:00 +0100
            Re: Question on CVE-2017-5754 on Debian 8.9 Nicholas Geovanis <nickgeovanis@gmail.com> - 2018-01-24 00:10 +0100
              Re: Question on CVE-2017-5754 on Debian 8.9 Jonathan Dowland <jmtd@debian.org> - 2018-01-24 11:20 +0100
                Re: Question on CVE-2017-5754 on Debian 8.9 Nicholas Geovanis <nickgeovanis@gmail.com> - 2018-01-24 17:10 +0100
                  Re: Question on CVE-2017-5754 on Debian 8.9 Nicholas Geovanis <nickgeovanis@gmail.com> - 2018-01-24 19:20 +0100
            Re: Question on CVE-2017-5754 on Debian 8.9 Nicholas Geovanis <nickgeovanis@gmail.com> - 2018-01-24 00:10 +0100
              Re: Question on CVE-2017-5754 on Debian 8.9 Michael Stone <mstone@debian.org> - 2018-01-24 00:20 +0100
                Re: Question on CVE-2017-5754 on Debian 8.9 Richard Hector <richard@walnut.gen.nz> - 2018-01-24 02:20 +0100
            Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 12:20 +0100
              Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 12:40 +0100
                Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 13:10 +0100
                  Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 13:50 +0100
                    Re: Question on CVE-2017-5754 on Debian 8.9 Sven Hartge <sven@svenhartge.de> - 2018-01-24 14:10 +0100
                      Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 14:30 +0100
                        Re: Question on CVE-2017-5754 on Debian 8.9 Sven Hartge <sven@svenhartge.de> - 2018-01-24 14:50 +0100
                          Re: Question on CVE-2017-5754 on Debian 8.9 Vincent Lefevre <vincent@vinc17.net> - 2018-01-24 15:20 +0100
                            Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 15:40 +0100
                              Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 17:10 +0100
                                Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 17:30 +0100
                                Re: Question on CVE-2017-5754 on Debian 8.9 Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-24 17:30 +0100
                                  Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 18:10 +0100
                                    Re: Question on CVE-2017-5754 on Debian 8.9 The Wanderer <wanderer@fastmail.fm> - 2018-01-24 18:30 +0100
                                    Re: Question on CVE-2017-5754 on Debian 8.9 Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-24 18:40 +0100
                                      Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 19:10 +0100
                                      Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 19:20 +0100
                                        Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 19:40 +0100
                                          Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 21:30 +0100
                                            Re: Question on CVE-2017-5754 on Debian 8.9 Michael Lange <klappnase@freenet.de> - 2018-01-24 23:40 +0100
                                              Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 02:00 +0100
                                                Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 10:40 +0100
                                                  Re: Question on CVE-2017-5754 on Debian 8.9 Michael Lange <klappnase@freenet.de> - 2018-01-25 11:00 +0100
                                                    Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 13:00 +0100
                                                      Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 14:00 +0100
                                                        Re: Question on CVE-2017-5754 on Debian 8.9 Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-25 14:10 +0100
                                                          Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 14:40 +0100
                                                            Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 17:20 +0100
                                                              Re: Question on CVE-2017-5754 on Debian 8.9 Michael Lange <klappnase@freenet.de> - 2018-01-25 18:30 +0100
                                                                Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 19:40 +0100
                                                                  Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 19:50 +0100
                                                                    Re: Question on CVE-2017-5754 on Debian 8.9 Michael Lange <klappnase@freenet.de> - 2018-01-25 22:00 +0100
                                                                  Re: Question on CVE-2017-5754 on Debian 8.9 Brian <ad44@cityscape.co.uk> - 2018-01-25 20:30 +0100
                                                                    Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 22:00 +0100
                                                              Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 18:40 +0100
                                                                Re: Question on CVE-2017-5754 on Debian 8.9 Michael Lange <klappnase@freenet.de> - 2018-01-25 22:10 +0100
                                                                  Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 23:10 +0100
                                                                    Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 23:30 +0100
                                                                      Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-25 23:40 +0100
                                                                    Re: Question on CVE-2017-5754 on Debian 8.9 Michael Lange <klappnase@freenet.de> - 2018-01-25 23:40 +0100
                                                                      Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-26 00:10 +0100
                                                                        Re: Question on CVE-2017-5754 on Debian 8.9 Michael Lange <klappnase@freenet.de> - 2018-01-26 00:20 +0100
                                  Re: Question on CVE-2017-5754 on Debian 8.9 Michael Fothergill <michael.fothergill@gmail.com> - 2018-01-24 18:30 +0100
                                  Re: Question on CVE-2017-5754 on Debian 8.9 Vincent Lefevre <vincent@vinc17.net> - 2018-01-25 15:30 +0100
                                    Re: Question on CVE-2017-5754 on Debian 8.9 Greg Wooledge <wooledg@eeg.ccf.org> - 2018-01-25 15:40 +0100
                                      Re: Question on CVE-2017-5754 on Debian 8.9 David Wright <deblis@lionunicorn.co.uk> - 2018-01-25 16:10 +0100
                                      Re: Question on CVE-2017-5754 on Debian 8.9 Vincent Lefevre <vincent@vinc17.net> - 2018-01-25 23:20 +0100
                                  Re: Question on CVE-2017-5754 on Debian 8.9 Jochen Spieker <ml@well-adjusted.de> - 2018-01-25 21:30 +0100
                                    Re: Question on CVE-2017-5754 on Debian 8.9 Sven Joachim <svenjoac@gmx.de> - 2018-01-25 21:40 +0100
                                    Re: Question on CVE-2017-5754 on Debian 8.9 Vincent Lefevre <vincent@vinc17.net> - 2018-01-25 23:40 +0100

Page 4 of 4 — ← Prev page 1 2 3 [4]


#191564

FromVincent Lefevre <vincent@vinc17.net>
Date2018-01-25 23:20 +0100
Message-ID<vbY2g-3hJ-69@gated-at.bofh.it>
In reply to#191535
On 2018-01-25 09:31:27 -0500, Greg Wooledge wrote:
> On Thu, Jan 25, 2018 at 03:24:21PM +0100, Vincent Lefevre wrote:
> > On 2018-01-24 11:19:36 -0500, Greg Wooledge wrote:
> > > To use a package from experimental, you must download it directly, and
> > > install it directly.  You don't use apt or its cousins, unless it's
> > > to backfill dependencies (apt-get -f install) from your actual release.
> > 
> > aptitude installs experimental packages automatically.
> 
> It is terrifying.
> 
> (Seriously, if you've configured it to do that, WHY?!?  Do you hate
> your computer so much that you want it to die?)

No, I certainly haven't configured it to do that. Well, I've added

deb http://ftp.fr.debian.org/debian/ experimental main
deb-src http://ftp.fr.debian.org/debian/ experimental main

to /etc/apt/sources.list, but the goal was just to be able to install
experimental packages *manually*, with an explicit request. The fact
that aptitude assumes that the user may want to upgrade unstable
packages to experimental automatically (in order to satisfy
dependencies) is a really bad feature.

-- 
Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)

[toc] | [prev] | [next] | [standalone]


#191544

FromJochen Spieker <ml@well-adjusted.de>
Date2018-01-25 21:30 +0100
Message-ID<vbWjL-26I-1@gated-at.bofh.it>
In reply to#191490

[Multipart message — attachments visible in raw view] — view raw

Greg Wooledge:
> 
> To use a package from experimental, you must download it directly, and
> install it directly.  You don't use apt or its cousins, unless it's
> to backfill dependencies (apt-get -f install) from your actual release.

Everything you wrote is correct but this paragraph.

You can use apt or aptitude for packages in experimental and I see no
reason against doing that. You do not even need to pin experimental.
Packages from experimental are automatically assigned priority 1, except
upgrades for packages that you installed from experimental.

That means you can add experimental to your sources.list and apt will
not automatically upgrade your packages from testing/sid to the versions
from experimental. But when you manually select a version from
experimental (using '-t experimantal'), apt will automatically upgrade
to newer versions available from experimental. And when testing/sid
contains a newer version, the one from experimental will be replaced by
that one.

J.
-- 
I am on the payroll of a company to whom I owe my undying gratitude.
[Agree]   [Disagree]
                 <http://archive.slowlydownward.com/NODATA/data_enter2.html>

[toc] | [prev] | [next] | [standalone]


#191546

FromSven Joachim <svenjoac@gmx.de>
Date2018-01-25 21:40 +0100
Message-ID<vbWtr-2aB-9@gated-at.bofh.it>
In reply to#191544
On 2018-01-25 21:20 +0100, Jochen Spieker wrote:

> You can use apt or aptitude for packages in experimental and I see no
> reason against doing that. You do not even need to pin experimental.
> Packages from experimental are automatically assigned priority 1, except
> upgrades for packages that you installed from experimental.

Packages installed from experimental also have priority 1.

> That means you can add experimental to your sources.list and apt will
> not automatically upgrade your packages from testing/sid to the versions
> from experimental. But when you manually select a version from
> experimental (using '-t experimantal'), apt will automatically upgrade
> to newer versions available from experimental.

No, it won't.  For that the priority needs to be at least 100, since
this is the priority of the version which is installed on the system.
See apt_preferences(5) and the blog at [1].

Cheers,
       Sven


1. http://petereisentraut.blogspot.de/2010/07/increasing-priority-of-debian.html

[toc] | [prev] | [next] | [standalone]


#191568

FromVincent Lefevre <vincent@vinc17.net>
Date2018-01-25 23:40 +0100
Message-ID<vbYlB-3o7-31@gated-at.bofh.it>
In reply to#191544
On 2018-01-25 21:20:23 +0100, Jochen Spieker wrote:
> You can use apt or aptitude for packages in experimental and I see no
> reason against doing that. You do not even need to pin experimental.
> Packages from experimental are automatically assigned priority 1, except
> upgrades for packages that you installed from experimental.
> 
> That means you can add experimental to your sources.list and apt will
> not automatically upgrade your packages from testing/sid to the versions
> from experimental. But when you manually select a version from
> experimental (using '-t experimantal'), apt will automatically upgrade
> to newer versions available from experimental. And when testing/sid
> contains a newer version, the one from experimental will be replaced by
> that one.

With aptitude, this is not true. See the discussions at:

  https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=795228
  https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=823928

-- 
Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)

[toc] | [prev] | [standalone]


Page 4 of 4 — ← Prev page 1 2 3 [4]

Back to top | Article view | linux.debian.user


csiph-web