Advice for building tomcat8 on jessie?

2018-06-30 Thread Roberto C . Sánchez
Hello Tomcat Maintainers, I have prepared a tomcat8 package for jessie (version 8.0.14-1+deb8u12) which addresses CVE-2018-1304 and CVE-2018-1305. When I try to build the package in a pbuilder chroot (invoked from gbp), the build fails. Here is the tail end of the build output: BUILD FAILED /bu

Re: qemu in jessie

2018-06-30 Thread Guido Günther
On Sat, Jun 30, 2018 at 05:42:37PM +0200, Santiago R.R. wrote: > Dear security team, > > I am working on the jessie package of qemu (the first time I work on > it), and I notice it hasn't been updated in jessie since May 2017. > There were various stretch updates since then, and I wonder if the >

qemu in jessie

2018-06-30 Thread Santiago R.R.
Dear security team, I am working on the jessie package of qemu (the first time I work on it), and I notice it hasn't been updated in jessie since May 2017. There were various stretch updates since then, and I wonder if the reason why jessie wasn't updated was mainly lack of time/resources, or is t

testing slurm-llnl for Jessie LTS

2018-06-30 Thread Thorsten Alteholz
Hi everybody, I uploaded version 14.03.9-5+deb8u3 of slurm-llnl to: https://people.debian.org/~alteholz/packages/jessie-lts/slurm-llnl/ Please give it a try and tell me about any problems you met. Thanks! Thorsten * CVE-2018-7033 Fix for issue in accounting_storage/mysql plugin by a

Jessie update of symfony?

2018-06-30 Thread Thorsten Alteholz
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Jessie version of symfony: https://security-tracker.debian.org/tracker/source-package/symfony Would you like to take care of this yourself? If yes, please follow the workflow we have de

Re: RFC: tomcat8 in the remaining jessie lifecycle

2018-06-30 Thread Roberto C . Sánchez
On Sat, Jun 30, 2018 at 04:24:24PM +0200, Markus Koschany wrote: > Am 30.06.2018 um 04:00 schrieb Roberto C. Sánchez: > [...] > > Comments and suggestions are most welcome. > > I would suggest to fix the open CVE via patches for now. Being EOL does > not necessarily mean that we cannot backport fi

Re: RFC: tomcat8 in the remaining jessie lifecycle

2018-06-30 Thread Markus Koschany
Am 30.06.2018 um 04:00 schrieb Roberto C. Sánchez: [...] > Comments and suggestions are most welcome. I would suggest to fix the open CVE via patches for now. Being EOL does not necessarily mean that we cannot backport fixes from the 8.5 branch but at some point upgrading from 8.x to 8.5 might be