Re: squeeze update of macopix?

2015-12-30 Thread Ying-Chun Liu (PaulLiu)
Ben Hutchings 於 2015年12月31日 06:37 寫道: > On Wed, 2015-12-30 at 20:19 +0800, Ying-Chun Liu (PaulLiu) wrote: > [...] >> I've made a patch. As attachment. > > I don't think it's a complete fix, as it doesn't check that there's > enough space for the terminating null (or shift sequence, where > needed)

squeeze update of tiff?

2015-12-30 Thread Ben Hutchings
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of tiff: https://security-tracker.debian.org/tracker/CVE-2015-7554 https://security-tracker.debian.org/tracker/CVE-2015-8665 https://security-tracker.debian.org/track

Re: squeeze update of tiff?

2015-12-30 Thread Ben Hutchings
On Wed, 2015-12-30 at 13:05 -0500, Jay Berkenbilt wrote: > Hello. I am no longer maintaining the tiff packages, but I have cc'ed > the new maintainers so that they can read the message quoted below and > respond if they are interested. I wonder whether it might make sense for > the debian-lts stuff

Re: squeeze update of macopix?

2015-12-30 Thread Ben Hutchings
On Wed, 2015-12-30 at 20:19 +0800, Ying-Chun Liu (PaulLiu) wrote: [...] > I've made a patch. As attachment. I don't think it's a complete fix, as it doesn't check that there's enough space for the terminating null (or shift sequence, where needed). > Should I just push it to unstable? Or I need t

Re: diff for passenger in Squeeze

2015-12-30 Thread Thorsten Alteholz
Hi Guido and Antoine, thanks alot for looking at the patch, yes I forgot an exclamation mark. The patch has not been tested yet (this is next on my agenda). I only wanted to make sure that I am on the right track. Indeed, between those versions there has been a major rewrite and the version in

Re: Updates to debian-security-support

2015-12-30 Thread Moritz Mühlenhoff
On Fri, Dec 18, 2015 at 12:10:09PM +0100, Raphael Hertzog wrote: > Hello, > > I pushed some updates to the git repository of debian-security-support > basically updating the status of virtualbox-ose in squeeze but also > handling some open bugs that various maintainers filed about their > own pack

squeeze update of inspircd?

2015-12-30 Thread Ben Hutchings
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of inspircd: https://security-tracker.debian.org/tracker/CVE-2015-8702 Would you like to take care of this yourself? If yes, please follow the workflow we have defi

Re: squeeze update of samba?

2015-12-30 Thread Santiago Ruano Rincón
Hi, El 18/12/15 a las 00:07, Jelmer Vernooij escribió: > Hi Raphael, > > On Wed, Dec 16, 2015 at 10:49:29PM +0100, Raphael Hertzog wrote: > > the Debian LTS team would like to fix the security issues which are > > currently open in the Squeeze version of samba: > > https://security-tracker.debian

Usertags for debian-lts

2015-12-30 Thread Guido Günther
Hi, In order to track the status of packaging improvements we make related to debian-lts I'd like to propose the "ease-lts" usertag: https://bugs.debian.org/cgi-bin/pkgreport.cgi?tag=ease-lts;users=debian-lts@lists.debian.org For issues related to prepare wheezy LTS the "prep-wheezy-lts":

Re: squeeze update of macopix?

2015-12-30 Thread Ying-Chun Liu (PaulLiu)
Ben Hutchings 於 2015年12月30日 09:49 寫道: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of macopix: > https://security-tracker.debian.org/tracker/CVE-2015-8614 > > Would you like to take care of this yoursel

RE: [pkg-mono-group] squeeze update of mono?

2015-12-30 Thread Jo Shields
My availability is crap right now due to new baby. Please, if nobody else in the Mono team rushes to upload a fix, I'd really appreciate it if the security or LTS team could help out Sent from my Sony Xperia™ smartphone Ben Hutchings wrote >Hello dear maintainer(s), > >the Debian LT

Re: squeeze update of claws-mail?

2015-12-30 Thread Ben Hutchings
On Wed, 2015-12-30 at 11:18 +0100, Ricardo Mones wrote: > Hi Ben et al, > > On Wed, Dec 30, 2015 at 01:48:47AM +, Ben Hutchings wrote: > > Hello dear maintainer(s), > > > > the Debian LTS team would like to fix the security issues which are > > currently open in the Squeeze version of claws-m

Re: squeeze update of macopix?

2015-12-30 Thread Ying-Chun Liu (PaulLiu)
Ben Hutchings 於 2015年12月30日 09:49 寫道: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of macopix: > https://security-tracker.debian.org/tracker/CVE-2015-8614 > > Would you like to take care of this yoursel

Re: squeeze update of claws-mail?

2015-12-30 Thread Ricardo Mones
On Wed, Dec 30, 2015 at 11:18:44AM +0100, Ricardo Mones wrote: […] > Both are still affected on current sid versions³⁴ and upstream⁵, not > sure whether that fact should be reflected on the same CVE. […] > ⁴ http://sources.debian.net/src/sylpheed/3.0.2-1/libsylph/codeconv.c/ This URL was wrongly

Re: squeeze update of claws-mail?

2015-12-30 Thread Ricardo Mones
Hi Ben et al, On Wed, Dec 30, 2015 at 01:48:47AM +, Ben Hutchings wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of claws-mail: > https://security-tracker.debian.org/tracker/CVE-2015-8614 AFAI

Re: squeeze/wheezy updates of Redmine (+ long term state of redmine packaging)

2015-12-30 Thread Raphael Hertzog
Hello Antoine, On Tue, 29 Dec 2015, anarcat wrote: > Hello dear maintainers of the Redmine packages! > > The Debian LTS team would like to fix the security issues which are > currently open in the Squeeze or Wheezy versions of redmine: I believe that Redmine is de-facto excluded from security su