Re: xen_4.1.6.1-1+deb7u2.dsc

2016-07-29 Thread Holger Levsen
On Fri, Jul 29, 2016 at 10:56:28PM +, Holger Levsen wrote: > while I'm glad that the xen upload will finally happen soon… oh, the joys of catching up on mails and reading not all mail before replying… in other words: thanks for the upload, Waldi! (+sorry for assuming the worst.) -- cheers,

Re: xen_4.1.6.1-1+deb7u2.dsc

2016-07-29 Thread Holger Levsen
Hi, while I'm glad that the xen upload will finally happen soon… On Fri, Jul 29, 2016 at 01:26:22PM +0200, Bastian Blank wrote: > > If Brian has no objections feel free to upload, Please let me know once > > done so I can then release the DLA (in case you don't want to handle it > > youself). > I

Re: Wheezy update of collectd?

2016-07-29 Thread Sebastian Harl
On Fri, Jul 29, 2016 at 09:43:39AM -0300, Lucas Kanashiro wrote: > On 07/28/2016 05:55 PM, Lucas Kanashiro wrote: > > On 07/28/2016 05:02 PM, Sebastian Harl wrote: > >> Thanks. I updated dla-needed. > >> > >> The fixed packages are ready for upload now. Please find the full > >> debdiff (source and

Re: CVE-2016-2313 fix wrong

2016-07-29 Thread Emilio Pozuelo Monfort
On 28/07/16 14:59, Matus UHLAR - fantomas wrote: >> On 28/07/16 13:35, Matus UHLAR - fantomas wrote: >>> i believe the fix for CVE-2016-2313 in >>> CVE-2016-2313-authentication-bypass.patch is invalid. > > On 28.07.16 14:26, Emilio Pozuelo Monfort wrote: >> Thanks for the report. I'll look at it l

Re: Wheezy update of collectd?

2016-07-29 Thread Lucas Kanashiro
On 07/28/2016 05:55 PM, Lucas Kanashiro wrote: > On 07/28/2016 05:02 PM, Sebastian Harl wrote: >> Thanks. I updated dla-needed. >> >> The fixed packages are ready for upload now. Please find the full >> debdiff (source and binary) attached to this email. Note that the >> (seemingly) added depende

Re: xen_4.1.6.1-1+deb7u2.dsc

2016-07-29 Thread Bastian Blank
Hi Guido On Fri, Jul 29, 2016 at 01:13:33PM +0200, Guido Günther wrote: > * the complete removal of tools/ioemu-qemu-xen - guess this was unused > anyway since quiet some time, right? I have no idea and found not one reference to that folder. > * there are some XSA related patches in debian/pa

Re: xen_4.1.6.1-1+deb7u2.dsc

2016-07-29 Thread Guido Günther
On Fri, Jul 29, 2016 at 12:15:49PM +0200, Bastian Blank wrote: > Hi Guido > > On Fri, Jul 29, 2016 at 11:48:16AM +0200, Guido Günther wrote: > > On Thu, Jul 28, 2016 at 10:26:23AM +0200, Bastian Blank wrote: > > > https://korte.credativ.com/~bbl/xen/xen_4.1.6.lts1-1.dsc > > Thanks but I get a 403

Re: xen_4.1.6.1-1+deb7u2.dsc

2016-07-29 Thread Bastian Blank
Hi Guido On Fri, Jul 29, 2016 at 11:48:16AM +0200, Guido Günther wrote: > On Thu, Jul 28, 2016 at 10:26:23AM +0200, Bastian Blank wrote: > > https://korte.credativ.com/~bbl/xen/xen_4.1.6.lts1-1.dsc > Thanks but I get a 403 on these. Could you adjust the permission so I > can grab the CVE nubmers f

Re: xen_4.1.6.1-1+deb7u2.dsc

2016-07-29 Thread Guido Günther
Hi Bastian, On Thu, Jul 28, 2016 at 10:26:23AM +0200, Bastian Blank wrote: > After receiving some testing, I made a release. > > https://korte.credativ.com/~bbl/xen/xen_4.1.6.lts1-1.dsc Thanks but I get a 403 on these. Could you adjust the permission so I can grab the CVE nubmers from the Changel

Re: Wheezy update of lighttpd?

2016-07-29 Thread Krzysztof Krzyżaniak
W dniu czw 28 lip, 2016 o 22∶36 użytkownik Thorsten Alteholz napisał: Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of lighttpd: https://u2049412.ct.sendgrid.net/wf/click?upn=d8cswn-2BnEH-2B7WbzLTEgT0MwTDeeK