[REQUEST FOR TESTING] libmtp 1.1.8-1+deb8u1

2020-03-28 Thread Dylan Aïssi
Hi all, I have prepared an update for libmtp to fix CVE-2017-9831 and CVE-2017-9832. * CVE-2017-9831: An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file allows attackers to cause a denial of service (out-of-bounds memory access) or

LTS report for January 2020

2020-02-01 Thread Dylan Aïssi
Hi, January was my 1st month as a Debian LTS paid contributor. I was assigned 8 hours and I spent 6.5 hours for the following: transfig: + Fixed CVE-2018-16140, CVE-2019-14275, CVE-2019-19555, tested, uploaded and released DLA. + Investigate CVE-2019-19746 and CVE-2019-19797, but they were not

Re: [SECURITY] [DLA 2069-1] cacti security update

2020-01-22 Thread Dylan Aïssi
Hi Chris, Le mer. 22 janv. 2020 à 12:11, Chris Lamb a écrit : > To prevent duplicated work, Dylan, just checking that you are either > aware of this thread and its context? It was, of course, my mistake > for not commenting and/or claiming it in dla-needed.txt. No problem, feel free to claim it

Re: Introduction new LTS trainee

2019-11-07 Thread Dylan Aïssi
Hi Sylvain, Le jeu. 7 nov. 2019 à 11:17, Sylvain Beucler a écrit : > Welcome! Thanks! > Having on board somebody who understands R sounds good ;) I don't know if this will really help :-). > Any past encounters with computer security? I have already backported some security fixes into Debian

Introduction new LTS trainee

2019-11-06 Thread Dylan Aïssi
Hi, After several emails exchanged with Holger and Raphaël, I am now a LTS trainee :-). I am still learning how to deal with the LTS workflow, so you can expect some questions from my side. Otherwise, I am DD since September 2018 and mainly involved in the Debian Med team and in the Debian R Pack

Re: Wheezy update of libofx?

2017-09-24 Thread Dylan Aïssi
Hi Thorsten, Sorry, I am completely snowed under with private life. So, please go ahead with libofx. Some links that could save your time: [1] is the upstream patch already apply in sid and buster. [2] is an example of ofx file that crash libofx. Best regards, Dylan [1] https://anonscm.debian.