Re: Roll existing backports into ELTS update for distro-info-data?

2022-10-31 Thread Holger Levsen
hi, first: thanks for maintaining d-i-d and for adding (E)LTS to it! On Sun, Oct 30, 2022 at 02:08:18PM +, Stefano Rivera wrote: > Back in those days, we used to publish distro-info-data updates via > backports, not stable updates. So there were backports published to both > stretch-backports

Cloud Store, découvrez de nouvelles solutions de productivité

2022-10-31 Thread Cloud Store
# # Bonjour Après ces années particulières, nous avons commercialisé, dans l'urgence, des solutions pour répondre à de nouvelles organisations du travail. Heureusement, nous les avions testé, éprouvé, depuis longtemps. Nous avons donc accompagné nos clients dans les meilleures conditions et

Re: Propose to ignore CVE-2022-41853 for hsqldb

2022-10-31 Thread Ola Lundqvist
Hi Good suggestion. I have added the package to dla-needed.txt and referred to this email chain. Cheers // Ola On Mon, 31 Oct 2022 at 13:53, Markus Koschany wrote: > Hi Ola, > > Am Montag, dem 31.10.2022 um 12:55 +0100 schrieb Ola Lundqvist: > > > > Any other thoughts? > > I agree this is a p

Re: Propose to ignore CVE-2022-41853 for hsqldb

2022-10-31 Thread Markus Koschany
Hi Ola, Am Montag, dem 31.10.2022 um 12:55 +0100 schrieb Ola Lundqvist: > > Any other thoughts? I agree this is a possible breaking change. I suggest we fix unstable first and investigate the further implications. I will do that soon. I have updated the security tracker with information about th

Propose to ignore CVE-2022-41853 for hsqldb

2022-10-31 Thread Ola Lundqvist
Hi fellow LTS developers I have looked at hsqldb and CVE-2022-41853. https://security-tracker.debian.org/tracker/CVE-2022-41853 >From the description it is clear that there are methods to configure the system to make it secure. The software change is to not allow any classes to be used by default