Re: Call for testing: db

2017-09-29 Thread Guido Günther
Hi, On Wed, Sep 27, 2017 at 06:48:07PM +0200, Emilio Pozuelo Monfort wrote: > Hi, > > I've prepared fixes for CVE-2017-10140 which affects src:db (5.1), src:db4.7 > and > src:db4.8 in wheezy. Of those, the most important one is src:db, which is the > one with actual reverse dependencies. However

Re: Fwd: Re: [Ticket#2017092834000757] Bug#876462: otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS

2017-09-29 Thread Markus Koschany
Am 29.09.2017 um 19:51 schrieb Markus Koschany: [...] > Apparently version 3.1.7 used the MyISAM engine which now conflicts with > the new default InnoDB database. I know how it could be fixed by hand > but I don't think this is the recommended Debian way. Do you have > encountered such a problem b

Re: Fwd: Re: [Ticket#2017092834000757] Bug#876462: otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS

2017-09-29 Thread Markus Koschany
Am 29.09.2017 um 12:11 schrieb Markus Koschany: > Am 29.09.2017 um 10:10 schrieb Patrick Matthäi: > [...] >> old-old-stable: You can use my work based on jessie, but there are some >> problems I see: >> - you have to drop the libjs-jquery-ui dependency, the removal of it in >> debian/rules, links i

Re: git-annex security issue backports

2017-09-29 Thread Salvatore Bonaccorso
Hi Antoine, On Thu, Sep 28, 2017 at 01:53:06PM -0400, Antoine Beaupré wrote: > Hi again, > > I reached out to joeyh to see how we could backport git-annex security > patches to wheezy. He responded by sharing the attached patch he sent to > the git-annex maintainer that backports the fixes to str

Re: Fwd: Re: [Ticket#2017092834000757] Bug#876462: otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS

2017-09-29 Thread Markus Koschany
Am 29.09.2017 um 10:10 schrieb Patrick Matthäi: [...] > old-old-stable: You can use my work based on jessie, but there are some > problems I see: > - you have to drop the libjs-jquery-ui dependency, the removal of it in > debian/rules, links in otrs2.links, patch 12 and 13, maybe more.. > - fonts-f

Re: Fwd: Re: [Ticket#2017092834000757] Bug#876462: otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS

2017-09-29 Thread Patrick Matthäi
Am 28.09.2017 um 16:23 schrieb Markus Koschany: > Am 28.09.2017 um 12:55 schrieb Patrick Matthäi: >> Uff, that is pretty much :/ >> >> >> >> Weitergeleitete Nachricht >> Betreff: Re: [Ticket#2017092834000757] Bug#876462: otrs2: >> CVE-2017-14635: Code Injection / Privilege Esc