Re: Wheezy update of hplip for CVE-2015-0839

2017-01-01 Thread Ola Lundqvist
Hi Sending it now. // Ola On 1 January 2017 at 11:07, Didier 'OdyX' Raboud wrote: > Hi Ola, > > Le jeudi, 29 décembre 2016, 22.52:00 h CET Ola Lundqvist a écrit : >> Some comments on the debdiff. >> >> The release name for wheezy is wheezy-security, not stable-security >> (nor oldstable-securit

Re: Wheezy update of hplip for CVE-2015-0839

2017-01-01 Thread Didier 'OdyX' Raboud
Hi Ola, Le jeudi, 29 décembre 2016, 22.52:00 h CET Ola Lundqvist a écrit : > Some comments on the debdiff. > > The release name for wheezy is wheezy-security, not stable-security > (nor oldstable-security). ACK. > Apart from that I think the change looks fine to me. Will you send out > the DLA

Re: Wheezy update of hplip for CVE-2015-0839

2016-12-29 Thread Ola Lundqvist
Hi Didier Some comments on the debdiff. The release name for wheezy is wheezy-security, not stable-security (nor oldstable-security). Apart from that I think the change looks fine to me. Will you send out the DLA regarding this or do you want me to do that? Please have a look here to see the wo

Wheezy update of hplip for CVE-2015-0839

2016-12-27 Thread Didier 'OdyX' Raboud
Dear LTS Team, I'd like to get CVE-2015-0839 fixed in wheezy, it's a no-DSA issue, and security team members suggested to get it fixed in stable and oldstable. This bug is a simple 'fetching gpg key from keyservers with a short keyid' problem, and upstream's fix is to use the full fingerprint. T