icu package and debdiff [new contributor, first attempt]

2016-05-07 Thread Roberto C . Sánchez
Hi All, I'm still "in-training" and I thought I would attempt to prepare an upload of the icu package for wheezy. The package is here: https://people.debian.org/~roberto/ dsc - https://people.debian.org/~roberto/icu_4.8.1.1-12+deb7u4.dsc debdiff - https://people.debian.org/~roberto/icu_4.8.1.1-12

Re: Wheezy update of ikiwiki?

2016-05-07 Thread Simon McVittie
On Sat, 07 May 2016 at 23:36:36 +0200, Markus Koschany wrote: > You are probably referring to CVE-2016-3714. Yes, that's the remote code execution flaw. There are also various less serious flaws discovered around the same time. > I'm not sure but wouldn't a > fix for ImageMagick also resolve this

Re: Wheezy update of ikiwiki?

2016-05-07 Thread Markus Koschany
Am 07.05.2016 um 22:38 schrieb Simon McVittie: > On Sat, 07 May 2016 at 20:52:16 +0200, Markus Koschany wrote: >> the Debian LTS team would like to fix the security issues which are >> currently open in the Wheezy version of ikiwiki: >> https://security-tracker.debian.org/tracker/CVE-2016-4561 > >

Re: Wheezy update of ikiwiki?

2016-05-07 Thread Simon McVittie
On Sat, 07 May 2016 at 22:59:49 +0200, Thorsten Alteholz wrote: > Hi Simon, > > On Sat, 7 May 2016, Simon McVittie wrote: > > That would probably be best if we're doing the ImageMagick mitigation; > > do you need to change something in ikiwiki to handle the ImageMagick CVEs? There doesn't seem t

Re: Wheezy update of ikiwiki?

2016-05-07 Thread Thorsten Alteholz
Hi Simon, On Sat, 7 May 2016, Simon McVittie wrote: That would probably be best if we're doing the ImageMagick mitigation; do you need to change something in ikiwiki to handle the ImageMagick CVEs? I'm not sure how much sense it makes to maintain webapps in LTS by backporting individual chan

Re: Wheezy update of ikiwiki?

2016-05-07 Thread Simon McVittie
On Sat, 07 May 2016 at 20:52:16 +0200, Markus Koschany wrote: > the Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of ikiwiki: > https://security-tracker.debian.org/tracker/CVE-2016-4561 I'm well aware of that vulnerability, having discovered

Wheezy update of ocaml?

2016-05-07 Thread Markus Koschany
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of ocaml: https://security-tracker.debian.org/tracker/CVE-2015-8869 Would you like to take care of this yourself? If yes, please follow the workflow we have defined

Wheezy update of jansson?

2016-05-07 Thread Markus Koschany
Hello dear maintainer, the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of jansson: https://security-tracker.debian.org/tracker/CVE-2016-4425 Would you like to take care of this yourself? If yes, please follow the workflow we have defined h

Wheezy update of ikiwiki?

2016-05-07 Thread Markus Koschany
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of ikiwiki: https://security-tracker.debian.org/tracker/CVE-2016-4561 Would you like to take care of this yourself? If yes, please follow the workflow we have define