Re: phpmyadmin / CVE-2016-9861 / PMASA-2016-66

2016-12-19 Thread Brian May
Brian May writes: > I have patched a number of vulnerabilities in phpmyadmin in wheezy; > there is a version available for testing at > https://people.debian.org/~bam/debian/pool/main/p/phpmyadmin/ > The included isAllowedDomain does not include some checks that are in > later versions: I have

Re: using existing workflows?

2016-12-19 Thread Ben Hutchings
On Sun, 2016-12-18 at 18:48 -0500, Antoine Beaupré wrote: > In working with the ImageMagick package, I noticed that the maintainer > uses gitpkg's debian/source/git-patches system to factor in upstream > patches in Debian. We haven't used this so far in the wheezy upload so I > kept working that wa

Re: wheezy update of nvidia-graphics-drivers 304.xx?

2016-12-19 Thread Markus Koschany
> For jessie, security bugs in the nonfree drivers are always handled as > no-dsa via stable-proposed-updates, but that way doesn't exist for > wheezy. How should we proceed here? Hi, thanks for your efforts. I suggest to upload the new packages to a place where people can download them from and

wheezy update of nvidia-graphics-drivers 304.xx?

2016-12-19 Thread Andreas Beckmann
Hi, we recently had some CVEs in the nvidia-graphics-drivers (the non-free blob driver) that would require updating to a new upstream release: * New upstream legacy 304xx branch release 304.134 (2016-12-14). * Fixed CVE-2016-8826. (Closes: #848195) - Added support for X.Org xserver AB

Wheezy update of samba?

2016-12-19 Thread Ola Lundqvist
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of samba: https://security-tracker.debian.org/tracker/CVE-2016-2125 Would you like to take care of this yourself? If yes, please follow the workflow we have defined

Re: using existing workflows?

2016-12-19 Thread Ola Lundqvist
Hi We usually have to learn a few odd things for some packages. The best guideline is probably to do it as simple as possible that works for this particular upload and package. For most packages it is not worth the effort to do any conversion, but some packages that typically get many CVEs it may

Re: [Debian-med-packaging] Wheezy update of dcmtk?

2016-12-19 Thread Bálint Réczey
Hi, 2016-12-19 9:10 GMT+01:00 Sébastien Jodogne : > Dear all, > >> On Sun, Dec 18, 2016 at 10:47:05PM +0100, Markus Koschany wrote: >> > Hello dear maintainer(s), >> > >> > the Debian LTS team would like to fix the security issues which are >> > currently open in the Wheezy version of dcmtk: >> >

Re: [Debian-med-packaging] Wheezy update of dcmtk?

2016-12-19 Thread Sébastien Jodogne
Dear all, On Sun, Dec 18, 2016 at 10:47:05PM +0100, Markus Koschany wrote: > > Hello dear maintainer(s), > > > > the Debian LTS team would like to fix the security issues which are > > currently open in the Wheezy version of dcmtk: > > https://security-tracker.debian.org/tracker/CVE-2015-8979 > >