Re: DLA documented

2014-07-18 Thread Moritz Mühlenhoff
On Tue, Jul 15, 2014 at 05:21:13PM +0200, Holger Levsen wrote: > Hi, > > On Dienstag, 15. Juli 2014, Moritz Muehlenhoff wrote: > > I don't think we should impose restrictions on the format of the mails. > > I think we absolutly should. We want consistend announcements, don't we? Not at the price

Re: cacti security update

2014-07-18 Thread Stefan Gundel
Am 15.07.2014 um 09:22 schrieb Paul Gevers : > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Package: cacti > Version: 0.8.7g-1+squeeze4 > CVE ID : CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 > CVE-2014-2708 CVE-2014-2709 CVE-2014-4002 > Debian Bug

Re: [SECURITY] [DSA 2974-1] php5 security update

2014-07-18 Thread Marko Randjelovic
Hi, Some patches from 5.4.4-14+deb7u12 could be unmodified or with modifications applied to 5.3.3-7+squeeze20. Some of them may be relevant for security. Since I am not a DD, patches I found could be useful are attached with eventual my modifications. I don't know if they solve the problems nor if

php5 for LTS

2014-07-18 Thread Thorsten Alteholz
Hi, this is my debdiff for fixing CVE-2014-3515, CVE-2014-0207, CVE-2014-3480 and CVE-2014-4721 in php5. Please give the packages from [1] some real-world testing before I upload them to squeeze-lts. Thanks! Thorsten [1] http://people.debian.org/~alteholz/packages/php5/ diff -u php5-5