Bug#782499: RM: multiple packages in squeeze-security

2015-04-13 Thread Raphaƫl Hertzog
Package: ftp.debian.org Severity: normal Hello, squeeze-security (on security.debian.org) contains packages which were dropped from squeeze (on main archive) because they are no longer supported. They should thus be also dropped from squeeze-security. I noticed at least: - bugzilla 3.6.2.0-4.4 -

squeeze update of dpkg?

2015-04-13 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of dpkg: https://security-tracker.debian.org/tracker/CVE-2015-0840 I had a quick look. The squeeze version of dpkg has a much more lax parser, so the issue might not

squeeze update of shibboleth-sp2?

2015-04-13 Thread Raphael Hertzog
Hello Ferenc, the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of shibboleth-sp2: https://security-tracker.debian.org/tracker/CVE-2015-2684 Would you like to take care of this yourself? We are still understaffed so any help is always highly

squeeze update of openldap?

2015-04-13 Thread Raphael Hertzog
Hello Luca & Ryan, the Debian LTS team would like to fix the security issue which is currently open in the Squeeze version of openldap: https://security-tracker.debian.org/tracker/CVE-2014-9713 Would you like to take care of this yourself? We are still understaffed so any help is always highly ap

Draft for a LTS press release

2015-04-13 Thread Raphael Hertzog
Hello everybody, following the recent discussion about wheezy LTS, we got a good suggestion to make some press release announcing that Wheezy and Jessie will benetift from LTS support and to use this opportunity to find more help for the project. I have thus written a first draft of such a press r

Re: Draft for a LTS press release

2015-04-13 Thread Neil McGovern
Hia, Thanks for thinking of press@ :) This seems a bit of a mix between a press release and a d-d-a posting. What are you after from this - are we announcing that LTS is happening for Wheezy/Jessie, or are we after a call for help? If the former, then we should definitely change quite a bit of t

Re: Draft for a LTS press release

2015-04-13 Thread Raphael Hertzog
Hi Neil, On Mon, 13 Apr 2015, Neil McGovern wrote: > This seems a bit of a mix between a press release and a d-d-a posting. > What are you after from this - are we announcing that LTS is happening > for Wheezy/Jessie, or are we after a call for help? Both! > If the former, then we should definit

Re: squeeze update of shibboleth-sp2?

2015-04-13 Thread Ferenc Wagner
Raphael Hertzog writes: > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of shibboleth-sp2: > https://security-tracker.debian.org/tracker/CVE-2015-2684 > > Would you like to take care of this yourself? We are still understaffed so > any

Re: About the security issues affecting openldap in Squeeze

2015-04-13 Thread Holger Levsen
Hi debian-edu, is anyone of you using Squeeze and able to test Ryans updated packages? If you are interested, please reply to Ryan directly. On Mittwoch, 8. April 2015, Ryan Tandy wrote: > >>We currently have a few patches pending or under discussion for > >>wheezy. After the changes for stable

Re: About the security issues affecting openldap in Squeeze

2015-04-13 Thread Ryan Tandy
On Mon, Apr 13, 2015 at 10:57:54PM +0200, Holger Levsen wrote: Ryan, I believe you might find some testers among the Debian Edu users, which uses openldap by default. Best if you couldd provide binary packages (amd64/i386) for download somewhere... Thanks for the suggestion. Uploaded UNRELEASED

Re: squeeze update of subversion?

2015-04-13 Thread James McCoy
On Fri, Apr 10, 2015 at 11:12:36PM +0200, Raphael Hertzog wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of subversion: > https://security-tracker.debian.org/tracker/CVE-2015-0248 > https://security

Re: squeeze update of shibboleth-sp2?

2015-04-13 Thread Raphael Hertzog
Hi, On Mon, 13 Apr 2015, Ferenc Wagner wrote: > I will help you as far as I can, but I'm no DD, so most of the > administrative work will stay on your shoulders. And I'm somewhat > uncertain whether a squeeze update would do much good without a > corresponding squeeze-backports fix. What do you