Re: Redundant emails - front desk

2016-07-20 Thread Raphael Hertzog
On Wed, 20 Jul 2016, Lucas Kanashiro wrote: > Sorry, I thought that I could help. I will not do any front desk work > again. Apologize. You are more than welcome to work again on LTS frontdesk, but you must register yourself in an unassigned week in org/lts-frontdesk-2016.txt and then there will

Re: Wheezy update of shadow?

2016-07-20 Thread Christian PERRIER
Quoting Chris Lamb (la...@debian.org): > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of shadow: > https://security-tracker.debian.org/tracker/CVE-2016-6251 > https://security-tracker.debian.org/tracker/CVE

Re: Redundant emails - front desk

2016-07-20 Thread Lucas Kanashiro
Sorry, I thought that I could help. I will not do any front desk work again. Apologize. Regards. On Wed, Jul 20, 2016, 18:50 Chris Lamb wrote: > > I tried to help with front desk work today > > May I ask why? There is a frontdesk "rota" to avoid duplicate work of > this sort and, as you have n

Re: Redundant emails - front desk

2016-07-20 Thread Chris Lamb
> I tried to help with front desk work today May I ask why? There is a frontdesk "rota" to avoid duplicate work of this sort and, as you have now noticed, there was not a significant backlog if any, especially with respect to issues that have no resolution and still need checking.. Regards, --

Redundant emails - front desk

2016-07-20 Thread Lucas Kanashiro
Hi, I tried to help with front desk work today, but unfortunately I sent some redundant emails because I did not realize that they had already been sent. Sorry, I'll take more care before start to send these kind of emails. Regards. -- Lucas Kanashiro 8ED6 C3F8 BAC9 DB7F C130 A870 F823 A272 98

Re: Wheezy update of kde4libs?

2016-07-20 Thread Maximiliano Curia
¡Hola Lucas! El 2016-07-20 a las 17:39 -0300, Lucas Kanashiro escribió: Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of shadow: https://security-tracker.debian.org/tracker/CVE-2016-6232 I think I might be

Re: Wheezy update of mat?

2016-07-20 Thread Lucas Kanashiro
On 07/20/2016 05:55 PM, intrigeri wrote: > Hi Lucas, > > Lucas Kanashiro wrote (20 Jul 2016 20:47:20 GMT) : >> the Debian LTS team would like to fix the security issues which are >> currently open in the Wheezy version of mat: >> https://security-tracker.debian.org/tracker/TEMP-0826101-4D75EC > Th

Re: Wheezy update of mat?

2016-07-20 Thread intrigeri
Hi Lucas, Lucas Kanashiro wrote (20 Jul 2016 20:47:20 GMT) : > the Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of mat: > https://security-tracker.debian.org/tracker/TEMP-0826101-4D75EC Thank you for caring! I'm not aware of any fix being

Re: Wheezy update of libjgroups-java?

2016-07-20 Thread Emmanuel Bourg
Le 20/07/2016 à 22:43, Lucas Kanashiro a écrit : > the Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of shadow: > https://security-tracker.debian.org/tracker/CVE-2016-2141 > > Would you like to take care of this yourself? Hi Lucas, I sugg

Wheezy update of openssh?

2016-07-20 Thread Lucas Kanashiro
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of openssh: https://security-tracker.debian.org/tracker/CVE-2016-6210 Would you like to take care of this yourself? If yes, please follow the workflow we have define

Wheezy update of libjgroups-java?

2016-07-20 Thread Lucas Kanashiro
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of shadow: https://security-tracker.debian.org/tracker/CVE-2016-2141 Would you like to take care of this yourself? If yes, please follow the workflow we have defined

Wheezy update of mat?

2016-07-20 Thread Lucas Kanashiro
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of mat: https://security-tracker.debian.org/tracker/TEMP-0826101-4D75EC Would you like to take care of this yourself? If yes, please follow the workflow we have defi

Wheezy update of extplorer?

2016-07-20 Thread Lucas Kanashiro
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of shadow: https://security-tracker.debian.org/tracker/CVE-2016-4313 Would you like to take care of this yourself? If yes, please follow the workflow we have define

Wheezy update of kde4libs?

2016-07-20 Thread Lucas Kanashiro
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of shadow: https://security-tracker.debian.org/tracker/CVE-2016-6232 Would you like to take care of this yourself? If yes, please follow the workflow we have define

Wheezy update of cakephp?

2016-07-20 Thread Lucas Kanashiro
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of cakephp: https://security-tracker.debian.org/tracker/CVE-2015-8379 https://security-tracker.debian.org/tracker/TEMP-000-698CF7 Would you like to take care of t

Wheezy update of pdns?

2016-07-20 Thread Lucas Kanashiro
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of pdns: https://security-tracker.debian.org/tracker/CVE-2016-6172 Would you like to take care of this yourself? If yes, please follow the workflow we have defined

Wheezy update of shadow?

2016-07-20 Thread Chris Lamb
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of shadow: https://security-tracker.debian.org/tracker/CVE-2016-6251 https://security-tracker.debian.org/tracker/CVE-2016-6252 Would you like to take care of this you

Re: Wheezy update of roundcube

2016-07-20 Thread Lucas Kanashiro
On 07/20/2016 02:23 PM, Markus Koschany wrote: > Hi, > > Feel free to work on everything you like. Fixing CVE-2014-9587 together > with CVE-2016-4069 isn't strictly required but you could probably reuse > some of your work if you try to tackle these issue. In any case the > whole CSRF complex req

Re: Wheezy update of roundcube

2016-07-20 Thread Markus Koschany
On 20.07.2016 18:51, Lucas Kanashiro wrote: > Hi Markus, > > > On 07/20/2016 01:12 PM, Markus Koschany wrote: >> Hello Lucas, >> >> I have prepared the last update of roundcube and just had a look at your >> patch. Unfortunately a proper fix for CVE-2016-4069 in Wheezy isn't as >> simple as it lo

Re: Wheezy update of roundcube

2016-07-20 Thread Lucas Kanashiro
Hi Markus, On 07/20/2016 01:12 PM, Markus Koschany wrote: > Hello Lucas, > > I have prepared the last update of roundcube and just had a look at your > patch. Unfortunately a proper fix for CVE-2016-4069 in Wheezy isn't as > simple as it looks like on first glance. The whole foundation to protect

Re: Wheezy update of roundcube

2016-07-20 Thread Markus Koschany
On 20.07.2016 16:33, Lucas Kanashiro wrote: [...] > I tested the upgrade of the previous version to this one and it worked. > I did some tests, but if you could review it I'll appreciate. > > After your feedback I can upload it or leave it up to you. > > Thank you very much. [...] Hello Lucas,

Wheezy update of roundcube

2016-07-20 Thread Lucas Kanashiro
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of roundcube: https://security-tracker.debian.org/tracker/CVE-2016-4069 I missed the first contact where I should answer if you want to do it or leave it to us, sorry

Re: Wheezy update of python-django?

2016-07-20 Thread Raphael Hertzog
Hi, On Tue, 19 Jul 2016, Chris Lamb wrote: > the Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of python-django: > https://security-tracker.debian.org/tracker/CVE-2016-6186 > > Would you like to take care of this yourself? I won't claim th

Re: CVE-2016-5387/apache2

2016-07-20 Thread Guido Günther
Hi Salvatore, On Wed, Jul 20, 2016 at 09:30:16AM +0200, Salvatore Bonaccorso wrote: > Hi LTS team, > > I have prepared an update for the mitigation of "httpoxy" in apache2 > (CVE-2016-5387). > > Unless someone of the team want's to actually do the upload I could do > it, since already prepared. B

dietlibc: insecure default PATH

2016-07-20 Thread Christian Seiler
Dear security and LTS teams, I'm co-maintainer of dietlibc. Thorsten Glaser has found a security issue that the default PATH (when the environment variable is NOT set) contains the current working directory. He has publicly reported this upstream under: http://news.gmane.org/find-root.php?message

Wheezy update of openssh?

2016-07-20 Thread Chris Lamb
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of openssh: https://security-tracker.debian.org/tracker/CVE-2016-6210 Would you like to take care of this yourself? If yes, please follow the workflow we have define

CVE-2016-5387/apache2

2016-07-20 Thread Salvatore Bonaccorso
Hi LTS team, I have prepared an update for the mitigation of "httpoxy" in apache2 (CVE-2016-5387). Unless someone of the team want's to actually do the upload I could do it, since already prepared. But just let me know. Regards, Salvatore diff -Nru apache2-2.2.22/debian/changelog apache2-2.2.22/