git-annex security issue backports

2017-09-28 Thread Antoine Beaupré
Hi again, I reached out to joeyh to see how we could backport git-annex security patches to wheezy. He responded by sharing the attached patch he sent to the git-annex maintainer that backports the fixes to stretch. I figured it would be useful for the core secteam to have visibilty on this... He

Re: Fwd: Re: [Ticket#2017092834000757] Bug#876462: otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS

2017-09-28 Thread Markus Koschany
Am 28.09.2017 um 12:55 schrieb Patrick Matthäi: > Uff, that is pretty much :/ > > > > Weitergeleitete Nachricht > Betreff: Re: [Ticket#2017092834000757] Bug#876462: otrs2: > CVE-2017-14635: Code Injection / Privilege Escalation OTRS > Datum:Thu, 28 Sep 2017 10:15:4

Fwd: Re: [Ticket#2017092834000757] Bug#876462: otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS

2017-09-28 Thread Patrick Matthäi
Uff, that is pretty much :/ Weitergeleitete Nachricht Betreff:Re: [Ticket#2017092834000757] Bug#876462: otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS Datum: Thu, 28 Sep 2017 10:15:49 + Von:Dusan Vuckovic via OTRS Security Team Organisation:

Re: Wheezy update of otrs2?

2017-09-28 Thread Patrick Matthäi
Hello Am 24.09.2017 um 23:45 schrieb Markus Koschany: > Dear maintainer(s), > > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of otrs2: > https://security-tracker.debian.org/tracker/source-package/otrs2 > > Would you like to take care of