Debian (E)LTS report for January 2025

2025-02-12 Thread Lee Garrett
Hi everyone, In January I released ansible-core 2.14.18-0+deb12u2 to bookworm [1] fixing: - CVE-2024-8775 - CVE-2024-9902 - CVE-2024-11079 This also included some updates to the autopkgtests. I also debugged and fixed some regressions caused by the dnsmasq/bookworm upload in December, which cau

Debian (E)LTS report for January 2025

2025-02-02 Thread Guilhem Moulin
During the month of January 2025 and on behalf of Freexian, I worked on the following: python-reportlab Uploaded 3.1.8-3+deb8u3 (jessie) and issued ELA-1289-1. https://www.freexian.com/lts/extended/updates/ela-1289-1-python-reportlab/ * CVE-2019-19450: Code injection in parapar

(E)LTS report for January 2025

2025-01-31 Thread Tobias Frost
I've worked during January 2025 on the below listed packages, for Freexian LTS/ELTS [1] Many thanks to Freexian and sponsors [2] for providing this opportunity! busybox (DLA-4019-1 ELA-1311-1) === This month I worked on busybox for LTS and ELTS, fixing 12-14 CVEs per

(E)LTS report for January 2024

2024-02-03 Thread Tobias Frost
I've worked during January 2024 on the below listed packages, for Freexian LTS/ELTS [1] Many thanks to Freexian and sponsors [2] for providing this opportunity! LTS and ELTS - paramiko - CVE-2023-48795 Unfortunatly only _after_ backporting the patch for CVE-2023-48795 (terrapin) and fighting wi

(E)?LTS report for january

2024-02-01 Thread Bastien Roucariès
I've worked during january on the below listed packages, for Freexian LTS/ELTS [1] Many thanks to Freexian and our sponsors [2] for providing this opportunity! ELTS: tinyxml -- Fix CVE-2023-34194 and release ELA-1029-1. Note that this project is dead upstram, but a fork seems ac

(E)LTS report for January 2023

2023-01-31 Thread Tobias Frost
I've worked during January 2023 on the below listed packages, for Freexian LTS/ELTS [1] Many thanks to Freexian and our sponsors [2] for providing this opportunity! LTS: - liapreq2: DLA-3269-1 (CVE-2022-22728) - libde265: DLA-3260-1 (see ELA for CVE list) - modsecurity-apache: DLA-3280-1

(E)LTS report for January

2022-02-14 Thread Emilio Pozuelo Monfort
Hi, During the month of January I worked on the following tasks for stretch LTS: - thunderbird 91 ESR update - thunderbird armhf failure - clamav security update - gdal security update - firefox-esr security update - thunderbird security update - pillow security update - openjdk-8 security updat

(E)LTS report for January 2021

2021-02-02 Thread Holger Levsen
hi, in January 2021 I spent 6.5h managing (E)LTS contributors: - dispatching work hours for LTS and ELTS - preparing the monthly Freexian blog post published on raphaelhertzog.com - prepare and run the monthly team meeting on irc - mail and irc communication, incl. - semi-automatic unclaim pack

(E)LTS report for January

2020-02-11 Thread Emilio Pozuelo Monfort
Hi, During January I spent 8 hours on LTS updating firefox, thunderbird, and firefox again, as well as fixing some problems with the VM. As for ELTS I spent 1.5h doing triaging work. Cheers, Emilio

(E)LTS report for January

2019-02-07 Thread Emilio Pozuelo Monfort
Hi, During the month of January, I spent 42.5 hours working on LTS on the following tasks: - thunderbird 60.4.0 ESR security update - tzdata and libdatetime-timezone-perl new releases - investigated symfony test failures - policykit-1 security update - investigated lua vulnerability, which didn'