Re: Wheezy update of firefox-esr?

2016-09-28 Thread Bálint Réczey
Hi, 2016-09-25 2:40 GMT+02:00 Mike Hommey : > On Sun, Sep 25, 2016 at 01:08:55AM +0200, Bálint Réczey wrote: >> Hi, >> >> 2016-09-24 15:34 GMT+02:00 Balint Reczey : >> > Hi, >> > >> > On 09/24/2016 12:51 AM, Mike Hommey wrote: >> >> On Fri, Sep 23, 2016 at 07:57:45PM +0200, Bálint Réczey wrote: >>

Re: chicken security update for Wheezy LTS

2016-09-28 Thread Bálint Réczey
2016-09-28 13:56 GMT+02:00 Bálint Réczey : > Hi, > > I have prepared an update for chicken in Wheezy. > > Please see the diff to previous version: > https://people.debian.org/~rbalint/ppa/wheezy-lts/chicken_4.7.0-1+deb7u1.patch.gz > > Changes: > chicken (4.7.0-1+deb7u1) wheezy-security; urgency=me

chicken security update for Wheezy LTS

2016-09-28 Thread Bálint Réczey
Hi, I have prepared an update for chicken in Wheezy. Please see the diff to previous version: https://people.debian.org/~rbalint/ppa/wheezy-lts/chicken_4.7.0-1+deb7u1.patch.gz Changes: chicken (4.7.0-1+deb7u1) wheezy-security; urgency=medium . * LTS Team upload * Don't overflow staticall

Re: Libavcodec being blacklisted with Firefox

2016-09-28 Thread Jean-Yves Avenard
On Wed, Sep 28, 2016 at 8:12 PM, Bálint Réczey wrote: > > Hi Jean-Yves Avenard, > > Please do so. Many minor issues get CVE id and it would be surprising > if one with such big consequences would be left without an id. The issue was raised at https://bugzilla.libav.org/show_bug.cgi?id=939 The i

Re: Libavcodec being blacklisted with Firefox

2016-09-28 Thread Bálint Réczey
Hi Jean-Yves Avenard, 2016-09-28 3:04 GMT+02:00 Jean-Yves Avenard : > Hi > > On Tue, Sep 27, 2016 at 7:54 PM, James Cowgill wrote: >> >> > We discovered a serious security vulnerability in libavcodec 54 and >> > earlier. Only libavcodec from LibAV is impacted.# >> >> What is the security vulnerab

wheezy-specific bind9 issue

2016-09-28 Thread Florian Weimer
While trying to write a reproducer for CVE-2016-2776, I discovered that the 1:9.8.4.dfsg.P1-6+nmu2+deb7u10 version in wheezy would crash, while unpatched jessie and upstream would not: This might be due to an incomplete fix for CVE-2015-