On 12 March 2017 at 16:44, Dirk Eddelbuettel wrote: | | On 12 March 2017 at 15:48, Markus Koschany wrote: | | Hello dear maintainer(s), | | | | the Debian LTS team would like to fix the security issues which are | | currently open in the Wheezy version of r-base: | | https://security-tracker.debian.org/tracker/CVE-2016-8714 | | | | Would you like to take care of this yourself? | | | | If yes, please follow the workflow we have defined here: | | https://wiki.debian.org/LTS/Development | | | | If that workflow is a burden to you, feel free to just prepare an | | updated source package and send it to debian-lts@lists.debian.org | | (via a debdiff, or with an URL pointing to the source package, | | or even with a pointer to your packaging repository), and the members | | of the LTS team will take care of the rest. Indicate clearly whether you | | have tested the updated package or not. | | | | If you don't want to take care of this update, it's not a problem, we | | will do our best with your package. Just let us know whether you would | | like to review and/or test the updated package before it gets released. | | | | You can also opt-out from receiving future similar emails in your | | answer and then the LTS Team will take care of r-base updates | | for the LTS releases. | | I can probably help as I was / am already in contact with Moritz from the | security team. | | (But I was also traveling for a family matter and had the misfortune of | seeing my server go off-grid. Back now.)
I managed to build a full set of the Debian stable version 3.1.1 plus two small and minimal patches. See here for all files: http://dirk.eddelbuettel.com/tmp/cve/ I am still awaiting feedback on this and haven't uploaded any to Debian yet. Dirk | Dirk | | | Thank you very much. | | | | Markus Koschany, | | on behalf of the Debian LTS team. | | | | PS: A member of the LTS team might start working on this update at | | any point in time. You can verify whether someone is registered | | on this update in this file: | | https://anonscm.debian.org/viewvc/secure-testing/data/dla-needed.txt?view=markup | | -- | http://dirk.eddelbuettel.com | @eddelbuettel | e...@debian.org -- http://dirk.eddelbuettel.com | @eddelbuettel | e...@debian.org