Re: Possible patch-backport problem for libphp-phpmailer (DLA-1591-1)

2018-12-10 Thread Chris Lamb
Hi Salvatore. > While preparing an update for libphp-phpmailer I noticed in the > patch/diff for DLA-1591-1 for libphp-phpmailer the following: Thanks for flagging. I will try and take a look at this over the next few days but I am pretty-solidly at a Reproducible Builds conference so if someone

Possible patch-backport problem for libphp-phpmailer (DLA-1591-1)

2018-12-10 Thread Salvatore Bonaccorso
Hi While preparing an update for libphp-phpmailer I noticed in the patch/diff for DLA-1591-1 for libphp-phpmailer the following: +--- libphp-phpmailer-5.2.9+dfsg.orig/class.phpmailer.php libphp-phpmailer-5.2.9+dfsg/class.phpmailer.php +@@ -1022,10 +1022,12 @@ class PHPMailer + +

LTS/ELTS Report for November 2018

2018-12-10 Thread Roberto C . Sánchez
For November I spent 13.75 hours on the following LTS tasks: - icu: triage CVE-2018-18928, vulnerable code was not present - libapache-mod-jk: prepared update for CVE-2018-11759 which involved backporting new upstream release; upload pending guidance from maintianers and security team on corre

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-10 Thread Moritz Mühlenhoff
On Mon, Dec 10, 2018 at 05:44:51PM +, Mike Gabriel wrote: > Hi, > > I'd like to discuss the possible pathways for getting FreeRDP fixed in > Debian jessie LTS (and Debian stretch, too). debian-security@ldo is not the proper contact address, I've fixed the recipient list. > Last week I talked

Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-10 Thread Mike Gabriel
Hi, I'd like to discuss the possible pathways for getting FreeRDP fixed in Debian jessie LTS (and Debian stretch, too). Last week I talked to Bernhard Miklautz (one of the FreeRDP upsteam maintainers and the actual packager of FreeRDPv2 in Debian). 1. Looking at fixing FreeRDP v1.1 in jes

unclaiming packages and monthly reports

2018-12-10 Thread Holger Levsen
hi, I just ran the weekly "./bin/review-update-needed --lts --unclaim 1814400 --exclude linux linux-4.9" and no package was claimed for 3 weeks without work or documenting progress, very good. ( With lowering this to two weeks 4 packages would be unclaimed, but let's not go there yet. ) In relate