Re: Please use clean chroot (sbuild/pbuilder/etc.) for LTS uploads

2016-09-19 Thread Jonas Meurer
Hi Balint, Am 19.09.2016 um 18:59 schrieb Bálint Réczey: > Please use clean chroot (sbuild/pbuilder/etc.) for LTS uploads. > This would prevent accidental regressions related to additional > installed packages or some VM related issues such as funny symlink > handling of vboxsf. So true, I just e

Re: graphicsmagick / CVE-2016-7447

2016-09-19 Thread Luciano Bello
On Monday 19 September 2016 18.25.31 Brian May wrote: > While the code is a significant improvement on the old code, does this > justify a security update? > > Possibly the answer is Yes, when combined with fixes for the other > security issues against graphicsmagick. Thought I should check here >

Re: graphicsmagick / CVE-2016-7447

2016-09-19 Thread GCS
On Mon, Sep 19, 2016 at 7:14 PM, Luciano Bello wrote: > On Monday 19 September 2016 18.25.31 Brian May wrote: >> While the code is a significant improvement on the old code, does this >> justify a security update? >> >> Possibly the answer is Yes, when combined with fixes for the other >> security

Please use clean chroot (sbuild/pbuilder/etc.) for LTS uploads

2016-09-19 Thread Bálint Réczey
Hi All, Please use clean chroot (sbuild/pbuilder/etc.) for LTS uploads. This would prevent accidental regressions related to additional installed packages or some VM related issues such as funny symlink handling of vboxsf. I have updated https://wiki.debian.org/LTS/Development with reminders. Th

Re: libarchive12: ldconfig warns that libarchive.so.12 is not a symbolic link

2016-09-19 Thread Jonas Meurer
Hello Bruce, Am 19.09.2016 um 14:47 schrieb Bruce Toll: > I reported a bug with the recent (Sept. 10) libarchive12 security update > (Debian BTS 838243) and heard back from Andreas Henriksson that I should > reach out to the package uploader and Debian LTS team directly. > > I appreciate the grea

Re: [SECURITY] [DLA 628-1] php5 security update

2016-09-19 Thread Jan Ingvoldstad
On 09/18/2016 05:12 PM, Thorsten Alteholz wrote: Package: php5 Version: 5.4.45-0+deb7u5 Thanks! * BUG-70436.patch Use After Free Vulnerability in unserialize() This one still has no CVE ID. * BUG-72681.patch PHP Session Data Injection Vulnerability, consume

libarchive12: ldconfig warns that libarchive.so.12 is not a symbolic link

2016-09-19 Thread Bruce Toll
Hello Jonas Meurer, I reported a bug with the recent (Sept. 10) libarchive12 security update (Debian BTS 838243) and heard back from Andreas Henriksson that I should reach out to the package uploader and Debian LTS team directly. I appreciate the great work that you and the LTS team are doing

Re: Wheezy update of icu?

2016-09-19 Thread Roberto C . Sánchez
I've prepared the last two LTS updates for icu, so I went ahead and claimed it dla-needed.txt. Unless there are any objections, I will begin preparing the update by the end of the week. Regards, -Roberto On Mon, Sep 19, 2016 at 09:29:24AM +0100, Chris Lamb wrote: > Hello dear maintainer(s), >

Wheezy update of icu?

2016-09-19 Thread Chris Lamb
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of icu: https://security-tracker.debian.org/tracker/source-package/icu Would you like to take care of this yourself? If yes, please follow the workflow we have defin