Re: dropbear 2012.55-1.3+deb7u2 to fix CVE-2017-9079

2017-05-20 Thread Guilhem Moulin
On Sat, 20 May 2017 at 21:37:02 +0200, Guilhem Moulin wrote: > Not sure how to tell the security tracker, though. Oops, just saw the docs :-P -- Guilhem. signature.asc Description: PGP signature

dropbear 2012.55-1.3+deb7u2 to fix CVE-2017-9079

2017-05-20 Thread Guilhem Moulin
Hi there, dropbear 2012.55-1.3+deb7u1 from wheezy-security is vulnerable to CVE-2017-9079. I backported the fix from 2017.75 to sid and jessie-security, and here is a debdiff against 2012.55-1.3+deb7u1. I also uploaded the source package to people.d.o, you'll find it at dget -x https://peop

testing bind9 for Wheezy LTS

2017-05-20 Thread Thorsten Alteholz
Hi everybody, I uploaded version 9.8.4.dfsg.P1-6+nmu2+deb7u16 of bind9 to: https://people.debian.org/~alteholz/packages/wheezy-lts/bind9/amd64/ Please give it a try and tell me about any problems you met. Thanks! Thorsten * Dns64 with "break-dnssec yes;" can result in a assertion failure.