Re: privoxy stretch package prepared

2021-02-06 Thread Utkarsh Gupta
Hi Roland, On Sun, Feb 7, 2021 at 2:18 AM Roland Rosenfeld wrote: > I changed "stretch" to "stretch-security", build again using -sa > optione and uploaded the result to security-master a minute ago. Great, thank you! I've rolled out the announcement and pushed the update for the website as well

Re: privoxy stretch package prepared

2021-02-06 Thread Roland Rosenfeld
Hi Utkarsh! On So, 07 Feb 2021, Utkarsh Gupta wrote: > Could you change "stretch" to "stretch-security" in the changelog, > re-build, and upload it to security-master? > In case you can't or lack the time, I shall be happy to do it myself > as well, let me know! :) I changed "stretch" to "stretc

Re: privoxy stretch package prepared

2021-02-06 Thread Utkarsh Gupta
Hi Roland, On Sun, Feb 7, 2021 at 1:19 AM Roland Rosenfeld wrote: > Shame on me, I simply overlooked it (for stretch and also for buster). No problem, thanks for the quick fix! :) > An updated diff is attached. This looks good. I did a build here, went through the logs (and autopkgtest), every

Re: privoxy stretch package prepared

2021-02-06 Thread Roland Rosenfeld
Hi Utkarsh! On Sa, 06 Feb 2021, Utkarsh Gupta wrote: > I have marked CVE-2020-20214 as not-affected in the tracker as you > mentioned but I can't seem to find the fix for CVE-2021-20215 in the > attached debdiff. Is there any reason for that as well? Or am I > missing something? Shame on me, I s

Re: privoxy stretch package prepared

2021-02-06 Thread Utkarsh Gupta
Hi Roand, On Sat, Feb 6, 2021 at 7:25 PM Utkarsh Gupta wrote: > I'll go through the patch and other things and will get back to you if > I have any questions or will upload as is :) I have marked CVE-2020-20214 as not-affected in the tracker as you mentioned but I can't seem to find the fix for

Re: privoxy stretch package prepared

2021-02-06 Thread Utkarsh Gupta
Hi Roland, On Sat, Feb 6, 2021 at 4:43 PM Roland Rosenfeld wrote: > As the maintainer of privoxy package, I just checked all new CVEs on > https://security-tracker.debian.org/tracker/source-package/privoxy and > prepared a stretch package with the patches fixing all CVEs. > > Only the patch for C