jessie update for mercurial

2018-06-06 Thread Antoine Beaupré
Hi! As part of the preparation work for jessie-lts, I started looking at the issues that were fixed in wheezy but not jessie. One of those is the mercurial package, which has been marked partly no-dsa, but also has simply unfixed issues. I have therefore worked on backporting the patches into jes

forward-ports to jessie

2018-06-06 Thread Antoine Beaupré
Hi, So on june 1st, a few changes were made to the security tracker that made it harder to figure out which packages can be forward-ported from Jessie, breaking the `lts-needs-forward-port.py` script. I have figured out how to reverse this locally, so if people want to work on that, here's how to

firebird2.5 / CVE-2017-11509

2018-06-06 Thread Brian May
Attached is my proposed patch for firebird2.5 in Jessie. Yes, I know this is no-DSA, however it is an easy change to make. I have made this change on wheezy. I plan on pushing these changes (maybe with UNRELEASED in the changelog) to the jessie branch in the Debian git respository, and I can also