10 msgRe: [SECURITY] [DSA 1565-1] New Linux 2.6.18 pa...
15 msgapt-get may accept inconsistent data
1 msgins
3 msg'unprivileged users may hijack forwarded X conn...

Re: [SECURITY] [DSA 1550-1] New suphp packages ...
\ Nicolas Boullis (28 Apr 2008)
. \ Adrian Minta (28 Apr 2008)
. . \ Nicolas Boullis (5 May 2008)
. \ Nico Golde (28 Apr 2008)

2 msgia32-lib plans and security support for same
1 msgContents.gz files in security repositories
2 msgRe: [SECURITY] [DSA 1534-2] New iceape packages...
1 msgRe: [SECURITY] [DSA 1557-1] New phpmyadmin pack...
2 msgRe: [SECURITY] [DSA 1556-1] New perl packages f...
1 msgRe: [SECURITY] [DSA 1555-1] New iceweasel packa...
3 msgpam_unix2 and xscreensaver password to restrictive
1 msgRe: [SECURITY] [DSA 1554-1] New roundup package...
11 msgKernel upgrade for 3Ware Driver issues?
2 msgMissing sparc binaries for DSA 1551-1 (python2.4)
3 msgRequest a security audit for my xiterm+thai pac...
1 msgAugmentez votre pouvoir d achat - Etude en lign...
3 msgRe: [SECURITY] [DSA 1548-1] New xpdf packages f...
2 msgRe: [SECURITY] [DSA 1553-1] New ikiwiki package...
7 msgClamAV concerns
Subject:Re: [SECURITY] [DSA 1550-1] New suphp packages fix local privilege escalation
Group:Debian-security
From:Nicolas Boullis
Date:5 May 2008


 
Hi,

Adrian Minta wrote:
>
> Try apache2-mpm-itk. Is better than suphp IMHO !

I saw it, but its description reads "Please note that this MPM is highly
experimental, and is not from the same tree as the other MPMs.", so I
did not consider using it on a production server.

For what it's worth, libapache2-mod-suphp has no such disclaimer, so I
considered it safer to use.

Anyway, I don't think a security update should break existing setups
like this one did.


Cheers,

Nicolas Boullis,
slightly disappointed

PS: sorry Adrian for the duplicate message, I did not intend to send
this message privately to you.


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com