Re: squeeze update of chrony?

2016-01-30 Thread Antoine Beaupré
On 2016-01-28 17:27:41, Vincent Blut wrote: > On Thu, Jan 28, 2016 at 09:23:01PM +0100, Guido Günther wrote: >>Hello dear maintainers, > > Hello Guido, > >>the Debian LTS team would like to fix the security issues which are >>currently open in the Squeeze version of chrony: >>https://security-track

Re: please test update to the icu package (CVE-2015-4844, CVE-2016-0494)

2016-01-30 Thread Antoine Beaupré
On 2016-01-30 13:17:09, Antoine Beaupré wrote: > I am still building the amd64 library here, I will put it online > there shortly. Those are now available as well. A. -- Pour marcher au pas d'une musique militaire, il n'y a pas besoin de cerveau, une moelle épinière suffit.

Re: squeeze update of prosody?

2016-01-30 Thread Antoine Beaupré
On 2016-01-30 14:25:50, Sergei Golovan wrote: >> Yet your patch says the source is "upstream"... could you clarify where >> it comes from or the rationale for this fix? > > See above. Great! Thanks for spending the time to clarify all this. I'll proceed with an upload as soon as I can test this.

Re: squeeze update of prosody?

2016-01-30 Thread Sergei Golovan
Hi Antoine, On Sat, Jan 30, 2016 at 9:45 PM, Antoine Beaupré wrote: > > It looks, however, that there's a bit missing in the patch... Upstream > seems to have made *two* patches to solve the issue. It looks like you > backported this: > > https://github.com/bjc/prosody/commit/8708def4f55e61acdd5b

Re: squeeze update of prosody?

2016-01-30 Thread Antoine Beaupré
On 2016-01-30 02:57:12, Sergei Golovan wrote: > Hi Guido, > > On Fri, Jan 29, 2016 at 11:10 AM, Guido Günther wrote: >> >> I would be great to have a "maintainer blessed" patch for that >> issue. Just send it to the list and we take care of the rest. > > Here are the .dsc and the .diff.gz for the

please test update to the icu package (CVE-2015-4844, CVE-2016-0494)

2016-01-30 Thread Antoine Beaupré
Hi, I have spent some time trying to untangle the patches for the `icu` package which has been noted as a priority package by LTS sponsors here. Two issues are pending in the package: https://security-tracker.debian.org/tracker/CVE-2015-4844 https://security-tracker.debian.org/tracker/CVE-2016-04

Re: squeeze update of phpmyadmin?

2016-01-30 Thread Michal Čihař
Hi Dne 29.1.2016 v 18:14 Guido Günther napsal(a): > Hello dear maintainer, > > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of phpmyadmin: > https://security-tracker.debian.org/tracker/CVE-2016-2039 > https://security-tracker.debian.o

Re: squeeze update of openssh?

2016-01-30 Thread Antoine Beaupré
On 2016-01-29 20:27:43, Colin Watson wrote: > On Fri, Jan 29, 2016 at 04:36:58PM -0500, Antoine Beaupré wrote: >> So this definitely need coordination with the openssh maintainers at >> this point, to at least confirm or infirm the "usability over security" >> decision that happened all that while

Re: Fixing CVE-2014-9674 (freetype) in wheezy

2016-01-30 Thread Sébastien Delafond
On Jan/30, Guido Günther wrote: > For some reason freetype in wheezy is a native package and I forgot > about that when rebuilding, sorry. Rebuilt and uploaded. This one's been accepted, thank you. I'll release the DSA either later today, or tomorrow morning. Cheers, --Seb

Re: triaging CVE-2016-1503+1504

2016-01-30 Thread Guido Günther
Hi, On Tue, Jan 26, 2016 at 07:55:02AM +, Mike Gabriel wrote: > HI Guido, > > On Mo 25 Jan 2016 20:44:34 CET, Guido Günther wrote: > > >Hi, > >looking at the above CVEs concerning dhcpcd, you wrote > > > ># Remove not-affected tags for squeeze. By simple code inspection we > ># cannot say th

Re: Fixing CVE-2014-9674 (freetype) in wheezy

2016-01-30 Thread Guido Günther
Hi, On Fri, Jan 29, 2016 at 07:52:17PM +0100, Sébastien Delafond wrote: > On Jan/29, Guido Günther wrote: > > urgency set to high and uploaded. Thanks a lot! > > the upload was rejected because it "Refers to non-existing file > 'freetype_2.4.9.orig.tar.gz'". Salvatore investigated and found out th