RFT: squid3 3.5.23-5+deb9u5, please test

2020-09-28 Thread Markus Koschany
[adding Andreas and Kevin to CC who helped with testing past squid3 updates] Hello, I have uploaded a new version of squid3 for Stretch to people.debian.org. https://people.debian.org/~apo/lts/squid3/stretch/ It contains fixes for CVE-2020-15049, CVE-2020-15810, CVE-2020-15811 and CVE-2020-2460

Re: [SECURITY] [DLA 2386-1] libdbi-perl security update

2020-09-28 Thread Sylvain Beucler
Hi, I don't see the need to show off my name once more (it's already in the header), especially when that name has little to do with who actually prepared the update, which is kinda misleading especially in DSAs. Cheers! Sylvain On 28/09/2020 23:42, Emilio Pozuelo Monfort wrote: > Hi Sylvain, >

Re: [SECURITY] [DLA 2386-1] libdbi-perl security update

2020-09-28 Thread Emilio Pozuelo Monfort
Hi Sylvain, On 28/09/2020 15:38, Sylvain Beucler wrote: > - > Debian LTS Advisory DLA-2386-1debian-lts@lists.debian.org > https://www.debian.org/lts/security/ > September 28, 2020htt

Bug#971264: mediawiki: ParseError after 1.27.7-1~deb9u4 upgrade (blame patch for User::pingLimiter)

2020-09-28 Thread carandraug
Package: mediawiki Version: 1:1.27.7-1~deb9u4 Severity: grave Justification: renders package unusable Dear Maintainer, After the update to 1.27.7-1~deb9u4 (from 1.27.7-1~deb9u3), the mediawiki site errors in all pages with: Exception encountered, of type "ParseError" Enabling some debug mes

Re: rails update

2020-09-28 Thread Sylvain Beucler
On 24/09/2020 23:14, Sylvain Beucler wrote: > Hi Security Team, > > On 15/07/2020 10:53, Moritz Muehlenhoff wrote: >> On Wed, Jul 15, 2020 at 09:03:01AM +0200, Sylvain Beucler wrote: >>> On 14/07/2020 22:29, Moritz Mühlenhoff wrote: On Fri, Jul 10, 2020 at 11:55:37AM +0200, Sylvain Beucler wr