Re: [SECURITY] [DSA 2974-1] php5 security update

2014-07-22 Thread Jan Ingvoldstad
On 22. juli 2014, at 13:45, Jan Ingvoldstad wrote: > It's a bit hard for me to read this, but I assume you're referring to DSA > 2974-1. Astute observation, Watson, you perceive that Marko mentioned this in the subject. D'oh. :) -- Cheers, Jan -- To UNSUBSCRIBE, email to debian-lts-requ.

Re: [SECURITY] [DSA 2974-1] php5 security update

2014-07-22 Thread Jan Ingvoldstad
On 18. juli 2014, at 16:28, Marko Randjelovic wrote: > Hi, Hi! > > Some patches from 5.4.4-14+deb7u12 could be unmodified or with > modifications applied to 5.3.3-7+squeeze20. Some of them may be > relevant for security. Since I am not a DD, patches I found could be > useful are attached with

Re: [SECURITY] [DSA 2974-1] php5 security update

2014-07-22 Thread Thorsten Alteholz
Hi, On Tue, 22 Jul 2014, Jan Ingvoldstad wrote: Several (if not all) of the issues in DSA 2974-1 are relevant to PHP 5.3.3. Three out of seven CVEs of DSA 2974-1 affect code that is not present in Squeeze. The remaining CVEs are part of the package I asked to test. The other patches don't h

Re: DLA documented

2014-07-22 Thread Holger Levsen
Hi, (adding listmasters@ to cc: again...) On Freitag, 18. Juli 2014, Moritz Mühlenhoff wrote: > > > I don't think we should impose restrictions on the format of the mails. > > I think we absolutly should. We want consistend announcements, don't we? > Not at the price of scaring away occasional LT

gen-DLA (was: Re: LTS-ID : LTS6A-2014-015)

2014-07-22 Thread Raphael Geissert
Hi, On Monday 14 July 2014 16:33:25 Holger Levsen wrote: > Index: data/DLA/list > === > --- data/DLA/list (revision 27711) > +++ data/DLA/list (working copy) > @@ -1,3 +1,5 @@ > +reserved DLA-0017-1 tor - new upstream vers

Re: gen-DLA (was: Re: LTS-ID : LTS6A-2014-015)

2014-07-22 Thread Holger Levsen
Hi, On Dienstag, 22. Juli 2014, Raphael Geissert wrote: > > +reserved DLA-0017-1 tor - new upstream version > > +reserved DLA-0016-1 libxml2 - security update > Could we please not have those "reserved" ids? just add the entry and use > it. sure. I think the distinction / meaning of "reserved" is

Re: Re: gen-DLA (was: Re: LTS-ID : LTS6A-2014-015)

2014-07-22 Thread Raphael Geissert
On Tuesday 22 July 2014 22:49:34 Holger Levsen wrote: > On Dienstag, 22. Juli 2014, Raphael Geissert wrote: > sure. I think the distinction / meaning of "reserved" is just > "unreleased"... Take a look at DLA/list's brother DSA/list; at times entries are added days in advance. Just make sure to u