description, fix lintian warning

This commit is contained in:
Patrick Schleizer 2019-10-18 10:36:44 +00:00
parent ce6b64a9ba
commit d301e7f365
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

8
debian/control vendored
View File

@ -42,8 +42,9 @@ Description: enhances misc security settings
. .
* The TCP/IP stack is hardened by disabling ICMP redirect acceptance, * The TCP/IP stack is hardened by disabling ICMP redirect acceptance,
ICMP redirect sending and source routing to prevent man-in-the-middle attacks, ICMP redirect sending and source routing to prevent man-in-the-middle attacks,
ignoring all ICMP requests, enabling TCP syncookies to prevent SYN flood attacks ignoring all ICMP requests, enabling TCP syncookies to prevent SYN flood
and enabling RFC1337 to protect against time-wait assassination attacks. attacks and enabling RFC1337 to protect against time-wait assassination
attacks.
. .
* Some data spoofing attacks are made harder. * Some data spoofing attacks are made harder.
. .
@ -61,7 +62,8 @@ Description: enhances misc security settings
* Kernel Page Table Isolation is enabled to mitigate Meltdown and increase * Kernel Page Table Isolation is enabled to mitigate Meltdown and increase
KASLR effectiveness. KASLR effectiveness.
. .
* SMT is disabled as it can be used to exploit the MDS and other vulnerabilities. * SMT is disabled as it can be used to exploit the MDS and other
vulnerabilities.
. .
* All mitigations for the MDS vulnerability are enabled. * All mitigations for the MDS vulnerability are enabled.
. .