Re: Fw: Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-09 Thread Salvatore Bonaccorso
Hi Andrea, On Mon, Jun 09, 2014 at 10:51:48PM +0200, Andrea Zwirner wrote: > Uops, I've erroneously sent this question to debian-security. They > will (justly) kill me! > > Before it happens, just let me ask you if fixing CVE-2014-3430 is > planned in LTS. :-) Yes, I plan to also upload dovecot

Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-09 Thread Paul Wise
On Tue, Jun 10, 2014 at 5:51 AM, Brandon Vincent wrote: > Squeeze-LTS is maintained by volunteers rather than the Debian > security team. If a package is released, a notification should be > posted to the debian-lts-announce mailing list. I guess you mean s/rather/other/ there? People are going

Re: Re: linux-2.6 (2.6.32-48squeeze7) CVE-2014-3153

2014-06-09 Thread Raphael Geissert
On Monday 09 June 2014 17:32:15 Dominic Hargreaves wrote: [...] > I noticed that lts-needed.txt says: > > "Some packages are not tracked here: > - Linux kernel (tracking in kernel-sec repo) > " > > What is the kernel-sec repo and how does it related to the above? It refers to this: https://aliot

Fw: Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-09 Thread Andrea Zwirner
Uops, I've erroneously sent this question to debian-security. They will (justly) kill me! Before it happens, just let me ask you if fixing CVE-2014-3430 is planned in LTS. :-) Thank you, Andrea Sent from my Sylpheed Begin forwarded message: Date: Mon, 9 Jun 2014 22:30:05 +0200 From:

Re: linux-2.6 (2.6.32-48squeeze7) CVE-2014-3153

2014-06-09 Thread Dominic Hargreaves
On Fri, Jun 06, 2014 at 02:06:37AM +0200, Carlos Alberto Lopez Perez wrote: > > I can see on the svn that the updated package for linux-2.6 is ready [1] > (or at least seems so) > [1] http://anonscm.debian.org/viewvc/kernel?view=revision&revision=21392 I noticed that lts-needed.txt says: "Some

Re: Missing openssl build for i386

2014-06-09 Thread Moritz Mühlenhoff
On Mon, Jun 09, 2014 at 12:53:34PM +1000, Matt Palmer wrote: > On Sat, Jun 07, 2014 at 10:45:25AM +0200, Jeroen Dekkers wrote: > > At Fri, 6 Jun 2014 08:04:38 +0200, > > Moritz Muehlenhoff wrote: > > > > > > On Fri, Jun 06, 2014 at 09:15:11AM +1000, Matt Palmer wrote: > > > > On Thu, Jun 05, 2014