Re: Urgency for uploads

2022-05-04 Thread Thijs Kinkhorst
On Wed, May 4, 2022 12:03, Moritz Muehlenhoff wrote: > Hi Enrico, > >> in the Developers's reference[1] it says, in boldface, that security >> updates should be built with "urgency=high". > > This is incorrect advice and I have idea where it came from. The urgency > is completely irrelevant for any

Re: Jessie update of simplesamlphp?

2019-05-28 Thread Thijs Kinkhorst
On Tue, May 28, 2019 16:01, Chris Lamb wrote: > Mike Gabriel wrote: > >> The Debian LTS team would like to fix the security issues which are >> currently open in the Jessie version of simplesamlphp: > > Which CVE is/was this for? I am just looking at: > > https://security-tracker.debian.org/track

Re: Upload mailman

2018-02-07 Thread Thijs Kinkhorst
Hi, On Wed, February 7, 2018 06:02, Abhijith PA wrote: > I prepared a LTS security update for mailman. Debdiff is attached. > link: > https://mentors.debian.net/debian/pool/main/m/mailman/mailman_2.1.15-1+deb7u3.dsc Looks good to me. Cheers, Thijs

Re: Bug#858539: should ca-certificates certdata.txt synchronize across all suites?

2018-01-12 Thread Thijs Kinkhorst
On Fri, January 12, 2018 10:24, Raphael Hertzog wrote: > Hi, > > On Tue, 09 Jan 2018, Brian May wrote: >> Raphael Hertzog writes: >> >> > I think this mail went through the cracks as we haven't received a >> reply >> > from you so far. Can you let us know the status and whether we can >> help to >

Re: Wheezy update of simplesamlphp?

2017-09-04 Thread Thijs Kinkhorst
Hi Raphael, On Wed, August 30, 2017 16:26, Raphael Hertzog wrote: > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of simplesamlphp: > https://security-tracker.debian.org/tracker/source-package/simplesamlphp > > Would you like to take car

Re: Security update of phpmyadmin for wheezy

2016-09-17 Thread Thijs Kinkhorst
On Thu, September 15, 2016 07:53, Thijs Kinkhorst wrote: > Hi Ola, > > On Wed, September 14, 2016 23:39, Ola Lundqvist wrote: >> I have prepared a security update of phpmyadmin for wheezy. > > Thank you for your work. > I plan to have all these issues reviewed o

Re: Security update of phpmyadmin for wheezy

2016-09-14 Thread Thijs Kinkhorst
Hi Ola, On Wed, September 14, 2016 23:39, Ola Lundqvist wrote: > I have prepared a security update of phpmyadmin for wheezy. Thank you for your work. I plan to have all these issues reviewed on Saturday at the latest. Cheers, Thijs

Re: Wheezy update of mailman?

2016-09-02 Thread Thijs Kinkhorst
On Thu, September 1, 2016 21:06, Chris Lamb wrote: > Hi Thijs, > >> > the Debian LTS team would like to fix the security issues which are >> > currently open in the Wheezy version of mailman: >> > https://security-tracker.debian.org/tracker/CVE-2016-6893 >> >> I'll look into it and will let you kno

Re: Wheezy update of mailman?

2016-08-27 Thread Thijs Kinkhorst
Hi Ben, On Sat, August 27, 2016 02:29, b...@decadent.org.uk wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of mailman: > https://security-tracker.debian.org/tracker/CVE-2016-6893 I'll look into it a

Re: testing php5 for Squeeze LTS

2016-02-28 Thread Thijs Kinkhorst
On Sat, February 27, 2016 22:38, Thorsten Alteholz wrote: > Hi everybody, > > I uploaded version 5.3.3.1-7+squeeze29 of php5 to: > https://people.debian.org/~alteholz/packages/squeeze-lts/php5/amd64/ > https://people.debian.org/~alteholz/packages/squeeze-lts/php5/i386/ > > Please give it a try

Re: Summary of the LTS BoF held during DebConf

2016-01-27 Thread Thijs Kinkhorst
On Tue, January 19, 2016 17:56, Santiago Ruano Rincón wrote: > Moreover, squeeze lts has been advertised to end next February, the 6th > to be precise. At the same time, the security team would support wheezy > until April 26th 2016, which is the Jessie release date + 1 year. What > do you think if

Re: squeeze update of commons-httpclient

2015-04-16 Thread Thijs Kinkhorst
On Wed, April 15, 2015 23:10, Markus Koschany wrote: > Hi, > > I have prepared a debdiff for commons-httpclient that addresses three > CVEs namely CVE-2012-5783, CVE-2012-6153 and CVE-2014-3577. The > differences between the versions in wheezy, jessie and sid are minor > since we use the same upstr

Re: squeeze update of phpmyadmin?

2015-02-24 Thread Thijs Kinkhorst
On Tue, February 24, 2015 16:54, Raphael Hertzog wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of phpmyadmin: > https://security-tracker.debian.org/tracker/CVE-2014-8958 > https://security-tracker.d

Re: Re: restarting services

2015-02-03 Thread Thijs Kinkhorst
On Tue, February 3, 2015 19:57, Isidor Zeuner wrote: >> From jessie and on I'd recommend "needrestart", which automatically runs >> after an APT run, prompts nicely about the services to restart and then >> actually does that. Very user-friendly. > > Sounds interesting. Can it also run in an unatte

Re: restarting services

2015-01-30 Thread Thijs Kinkhorst
On Fri, January 30, 2015 11:05, Jan Wagner wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > Hi Isidor, > > Am 30.01.15 um 07:15 schrieb Isidor Zeuner: >> However, I wondered if it wouldn't be appropriate to have the >> upgrade restart the services which link to libc6? Otherwise, >> ru

Re: eglibc update for GHOST CVE-2015-0235

2015-01-28 Thread Thijs Kinkhorst
On Wed, January 28, 2015 11:29, Lucas Nussbaum wrote: > Yes, I was wondering how we could improve on the current status for the > handling of medium/high-severity issues, and I'm interested in the > Debian security team's opinion about that. > > Should the Debian LTS team apply to join the linux-di

Re: testing php5 for Squeeze LTS

2014-11-23 Thread Thijs Kinkhorst
On Sun, November 23, 2014 19:37, Thorsten Alteholz wrote: > I uploaded version 5.3.3-7+squeeze23 of php5 to: > https://people.debian.org/~alteholz/packages/squeeze-lts/php5/amd64/ > > Please give it a try and tell me about any problems you met No problems found in my setup. Thijs -- To UNSU

Re: new packages for libxml2

2014-10-28 Thread Thijs Kinkhorst
On Tue, October 28, 2014 22:57, Thorsten Alteholz wrote: > Hi, > > new packages for libxml2 can be found at [1]. > > Can you please test them and give some feedback whether they are ready for > upload? >From looking at the diff they seem fine. It also installs ok but I do not have any serious xml

Re: Please test new apache2 2.2.16-6+squeeze14

2014-10-15 Thread Thijs Kinkhorst
On Wed, October 15, 2014 14:22, Raphael Hertzog wrote: > Hello, > > I have prepared a new upload of apache2 to fix CVE-2014-3581 and > CVE-2013-5704 in squeeze-lts. The debdiff is attached and I have put amd64 > package for test online. Grab them with dget > https://people.debian.org/~hertzog/packa

Re: Invalid HTTP requests from apt, introduced by DLA 58-1

2014-10-14 Thread Thijs Kinkhorst
On Tue, October 14, 2014 09:07, Jan Wagner wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > Am 13.10.14 15:04, schrieb Raphael Hertzog: >> On Mon, 13 Oct 2014, Raphael Hertzog wrote: >>> BTW, Michael responded to me: Indeed, this looks like a bug in the patch, sorry for that. I >

Re: Interest in ia32-libs for squeeze-lts

2014-09-03 Thread Thijs Kinkhorst
On Fri, July 11, 2014 10:51, Thomas Goirand wrote: > On 07/11/2014 02:55 PM, Thijs Kinkhorst wrote: >> I was wondering if there's interest for the ia32-libs package to be >> maintained in squeeze-lts. > Well, having it up-to-date is good, With "is good", you mean

Re: Bug#760358: please add [SECURITY] subject prefix for debian-lts-announce

2014-09-03 Thread Thijs Kinkhorst
On Wed, September 3, 2014 13:31, Alexander Wirt wrote: >> Desired situation: >> >> Subject: [SECURITY] [DSA 3017-1] php-cas security update >> Subject: [SECURITY] [DLA 43-1] eglibc security update > Done, but untested. Please test this as soon as possible. Works as designed, thank you! Thijs

please add [SECURITY] subject prefix for debian-lts-announce

2014-09-03 Thread Thijs Kinkhorst
Package: lists.debian.org Severity: wishlist Hi, Can you please configure the debian-lts-announce list so it has a subject prefix "[SECURITY] ", in the same way that debian-security-announce has? Current difference between d-s-a and d-l-a: Subject: [SECURITY] [DSA 3017-1] php-cas security upda

Re: eglibc update addressing CVE-2014-5119?

2014-09-01 Thread Thijs Kinkhorst
Op maandag 1 september 2014 19:19:26 schreef Thorsten Alteholz: > On Thu, 28 Aug 2014, Jan Ingvoldstad wrote: > > Is an eglibc update for the privilege escalation attack forthcoming? > > I uploaded packages to [1]. Maybe someone can give them a try before I > upload them to the archive. I have g

Re: squeeze-lts and the security tracker

2014-08-06 Thread Thijs Kinkhorst
On Wed, August 6, 2014 10:20, Holger Levsen wrote: > Hi Florian, > > On Dienstag, 5. August 2014, Florian Weimer wrote: >> > Having the oldstable tracker working would be really useful to pick >> > packages to work on... >> There's some code that assumes that oldstable has a security archive, >> wh

Interest in ia32-libs for squeeze-lts

2014-07-10 Thread Thijs Kinkhorst
All, I was wondering if there's interest for the ia32-libs package to be maintained in squeeze-lts. The ia32-libs package contains 32 bit versions of various libraries which can be installed on amd64, so you can run 32 bit applications that do not have a 64 bit equivalent on your 64 bit system. I

Re: Fw: Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-11 Thread Thijs Kinkhorst
On Wed, June 11, 2014 09:14, Salvatore Bonaccorso wrote: > Before I release the package, if somebody has a further dovecot > instance running under squeeze there are prepared packages for amd64 > under: > > http://people.debian.org/~carnil/tmp/dovecot/ Confirmed that it would without problems in o

Re: Workflow for Debian LTS / First update released

2014-06-02 Thread Thijs Kinkhorst
On Mon, June 2, 2014 09:59, Moritz Muehlenhoff wrote: > Everyone who wants to participate should request write access to that > repo, as documented here: > https://security-tracker.debian.org/tracker/data/report Note that all DD's should already be able to commit to this repository without request