LTS/subversion note

2019-08-14 Thread Roberto C . Sánchez
Chris, I decided to take a shot fixing CVE-2018-11782 and CVE-2019-0203 for subversion in jessie. You had made the following note in dla-needed.txt: subversion NOTE: 20190804: For (at least) CVE-2018-11782 the svn_err_trace that is in the diff has not been added yet. (lamby) I spent some tim

Re: LTS update for openldap?

2019-08-14 Thread Markus Koschany
Hello Ryan, Am 14.08.19 um 21:36 schrieb Ryan Tandy: > Dear LTS team, > > I propose updating openldap in jessie to fix two no-DSA CVEs and one > additional important bug. The same changes have been accepted for the > next point releases of buster (#934507) and stretch (#934508). > > The issues a

LTS update for openldap?

2019-08-14 Thread Ryan Tandy
Dear LTS team, I propose updating openldap in jessie to fix two no-DSA CVEs and one additional important bug. The same changes have been accepted for the next point releases of buster (#934507) and stretch (#934508). The issues all affect specific, mostly uncommon, slapd configurations, whic