Re: squeeze update of libgtk2-perl?

2015-02-24 Thread intrigeri
Raphael Hertzog wrote (24 Feb 2015 17:03:27 GMT) : > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of libgtk2-perl: Great, thanks for your work :) > Would you like to take care of this yourself? I prepared and tested the fixes for cur

Re: squeeze update of p7zip?

2015-02-24 Thread Mohammed Adnène Trojette
On Tue, Feb 24, 2015, Raphael Hertzog wrote: > If you don't want to take care of this update, it's not a problem, we > will do our best with your package. Just let us know whether you would > like to review and/or test the updated package before it gets released. Bonsoir Raphael and LTS team, I g

Re: Bug#778634: squeeze update of libphp-snoopy?

2015-02-24 Thread Marcelo Jorge Vieira
Hi, On Tue, 2015-02-24 at 16:07 +0100, Raphael Hertzog wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of libphp-snoopy: > https://security-tracker.debian.org/tracker/CVE-2014-5008 > https://securit

squeeze update of pound?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of pound: https://security-tracker.debian.org/tracker/source-package/pound Would you like to take care of this yourself? We are still understaffed so any help is alw

squeeze update of p7zip?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of p7zip: https://security-tracker.debian.org/tracker/CVE-2015-1038 Would you like to take care of this yourself? We are still understaffed so any help is always hig

squeeze update of mod-gnutls?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of mod-gnutls: https://security-tracker.debian.org/tracker/source-package/mod-gnutls Would you like to take care of this yourself? We are still understaffed so any h

Re: squeeze update of libspring-2.5-java?

2015-02-24 Thread Emmanuel Bourg
Hi Raphael, CVE-2011-3923 seems to be a Struts vulnerability, why is it assigned to Spring? Emmanuel Bourg PS: pkg-java-maintain...@lists.alioth.debian.org is mainly a notification list, most of the Java maintainers do not read it. I suggest posting your update requests to debian-j...@lists.debi

squeeze update of libgtk2-perl?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of libgtk2-perl: https://security-tracker.debian.org/tracker/source-package/libgtk2-perl https://security-tracker.debian.org/tracker/TEMP-000-1541B5 Would you li

Re: Bug#773834: Preparing a release for stable and lts

2015-02-24 Thread Raphael Hertzog
On Wed, 24 Dec 2014, Bastien ROUCARIES wrote: > Hi, > > I am now doing my home work for stable and lts Hello Bastien, thanks for caring about stable and lts! But it looks like this fell through the cracks. Do you still intend to work on such updates? If yes, have a look at the workflow describe

Re: [CVE-2014-0109] qt4-x11_4.6.3-4+squeeze3_CVE-2014-0190

2015-02-24 Thread Raphael Hertzog
Hello ies, I just stumbled upon the fact that in dla-needed.txt you are still marked as working on preparing a qt4-x11 update but it looks like you did not make any progress recently. On Thu, 29 Jan 2015, ies wrote: > I have just fixed the CVE for the qt4-x11 of the minor security issue. > > Ple

Re: squeeze update of phpmyadmin?

2015-02-24 Thread Thijs Kinkhorst
On Tue, February 24, 2015 16:54, Raphael Hertzog wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of phpmyadmin: > https://security-tracker.debian.org/tracker/CVE-2014-8958 > https://security-tracker.d

Bug#779104: debian-security-support: Please mark piwigo as not supported in squeeze

2015-02-24 Thread Raphaël Hertzog
Package: debian-security-support Version: 2014.12.17 Severity: normal Please mark piwigo as no longer supported in Debian 6 Squeeze. The package has no Debian maintainer since it's not in wheezy, jessie and sid. It does still exist in squeeze for historical reasons but we should not claim that we

squeeze update of phpmyadmin?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of phpmyadmin: https://security-tracker.debian.org/tracker/CVE-2014-8958 https://security-tracker.debian.org/tracker/CVE-2014-9218 Would you like to take care of thi

squeeze update of libspring-2.5-java?

2015-02-24 Thread Raphael Hertzog
[ CC Damien Raude-Morvan who handled the last security upload ] Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of libspring-2.5-java (this source package only exists in squeeze currently): https://security-tra

squeeze update of libphp-snoopy?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of libphp-snoopy: https://security-tracker.debian.org/tracker/CVE-2014-5008 https://security-tracker.debian.org/tracker/CVE-2008-7313 Would you like to take care of

squeeze update of libjson-ruby?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of libjson-ruby (package is no longer in unstable under that name): https://security-tracker.debian.org/tracker/CVE-2013-0269 Would you like to take care of this you

squeeze update of libnokogiri-ruby?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of your package: https://security-tracker.debian.org/tracker/CVE-2012-6685 Would you like to take care of this yourself? If yes, please follow the workflow we have

squeeze update of konversation?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of konversation: https://security-tracker.debian.org/tracker/CVE-2014-8483 Would you like to take care of this yourself? We would really appreciate it because that i

squeeze update of jruby?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of your jruby: https://security-tracker.debian.org/tracker/CVE-2012-5370 https://security-tracker.debian.org/tracker/CVE-2011-4838 Would you like to take care of thi

About the security issues affecting ejabberd in Squeeze

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team recently reviewed the security issue(s) affecting your package in Squeeze: https://security-tracker.debian.org/tracker/CVE-2014-8760 We decided that we would not prepare a squeeze security update (usually because the security impact is low and that we

security update of commons-httpclient?

2015-02-24 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of your commons-httpclient: https://security-tracker.debian.org/tracker/CVE-2012-6153 It would be nice if you could take care of this update as the package is not hi

Thanks Debian LTS team

2015-02-24 Thread Laura Arjona Reina
Dear LTS Team Yesterday I upgraded at work the two machines that still were in Squeeze (LTS), to Wheezy. The migration has worked perfectly. And this last year following the list and the blog updates, applying the patches that you provide (thanks! kudos!), and having "peace of mind" while preparing

Re: Want to help with CVE triaging?

2015-02-24 Thread DIXLOR
24.02.2015 14:07, Raphael Hertzog пишет: Hello, one part of the process was not yet very well documented, it's the part about CVE triaging. I just fixed this by adding a new section to https://wiki.debian.org/LTS/Development (and at the same time I did some other cleanups/improvements). So if

Want to help with CVE triaging?

2015-02-24 Thread Raphael Hertzog
Hello, one part of the process was not yet very well documented, it's the part about CVE triaging. I just fixed this by adding a new section to https://wiki.debian.org/LTS/Development (and at the same time I did some other cleanups/improvements). So if you want to help with CVE triaging, you're w