Hallo Oleksandr, I just saw that you have a LowNMU policy, but you'd like to be contacted before doing the actual NMU.
Well, I'm currently preparing a NMU for the lcms* to fix some CVE and a
fatal lintian error. Please feel
(* I'm talking about the "old" lcms-1, not the lcms2 ... just to avoid
confusion)
Please note that I cannot upload the NMU by myself, so I will ask my AM,
Thijs Kinkhorst (CC'ed) to put the upload into DELAYED/8 if he approves
(and you not vetoing).
I've choosen DELAYED/8 because I will be away from computers starting
tomorrow for a week, and I'd like to be available when the package
enters the queue.
This is the current changelog for the intended NMU:
lcms (1.19.dfsg1-1.3) unstable; urgency=medium
* Non-maintainer upload.
* Apply fix from OpenSuse for CVE-2013-4276 (Closes: #718682)
* Repack orig-source to remove non-dfsg free color profiles. This is
necessary as the resulting lintian error
license-problem-md5sum-non-free-file would lead to an autoreject
(Closes: #736806).
* Fix CVE-2013-4160 by backporting the fix from lcms-2 (Closes:
#728208)
-- Tobias Frost <[email protected]> Thu, 27 Mar 2014 12:20:24 +0100
I already attached the patches I will use for the CVS's to the BTS,
but of course I will also send an complete nmudiff later to the BTS.
Best regards,
--
Tobi
signature.asc
Description: This is a digitally signed message part

