Re: [SECURITY] [DSA 4371-1] apt security update

2019-01-24 Thread Emilio Pozuelo Monfort
Hi Steve, On 22/01/2019 14:50, Steve McIntyre wrote: > On Tue, Jan 22, 2019 at 01:44:12PM +, Ben Hutchings wrote: >> However, APT is used during initial installation and we don't have any >> provision for updating installer images during LTS. So we're either >> going to have to revisit that o

Re: tmpreaper jessie update

2019-01-24 Thread Hugo Lefeuvre
Hi Moritz, > The new libmount dependency is necessary for the new check used by the > security > fix. Most of the additional autoconf noise is related to that new dependency > and to the fact that the last upload to unstable before the 1.6.14 one was in > 2010. > > If the debdiff for jessie is

Re: tmpreaper jessie update

2019-01-24 Thread Moritz Muehlenhoff
On Thu, Jan 24, 2019 at 09:16:37AM +0100, Hugo Lefeuvre wrote: > Dear security team, > > I'm currently preparing a jessie security update addressing CVE-2019-3461, > based on 1.6.13+nmu1+deb9u1 (stretch version). > > I see that the diff is quite huge (same code as buster 1.6.14 right?) and > adds

tmpreaper jessie update

2019-01-24 Thread Hugo Lefeuvre
Dear security team, I'm currently preparing a jessie security update addressing CVE-2019-3461, based on 1.6.13+nmu1+deb9u1 (stretch version). I see that the diff is quite huge (same code as buster 1.6.14 right?) and adds a new libmount-dev dependency. I've had a look at the diff, tested it in jes