Re: Analysis of issue for phpmyadmin and request for comment on XSS issues

2016-07-02 Thread Ola Lundqvist
Hi Markus and Ben Thanks to both of you for good insight. Markus you gave a good reminder that XSS is also for people who have "write permission" to the site. I'll use both your inputs in the further patch work. The XSS issues looks trivial so I should be able to fix all or most of them easily.

LTS report for June 2016

2016-07-02 Thread Emilio Pozuelo Monfort
This month I was allocated 16 hours to work on Debian-LTS. I spent this time doing the following: - Prepared, tested and uploaded libxslt. - Prepared and tested an update for clamav. However the maintainer asked me to wait until a regression in the Jessie update can be addressed. - Prepared, teste

sqlite3 package and debdiff [new-ish contributor, second attempt]

2016-07-02 Thread Roberto C . Sánchez
Hello all, As the ICU package was perhaps a bit much to try as a first attempt (I am still waiting for feedback from upstream on the patches as I am unable to test them), I have decided to tackle a less challenging package for my training run: sqlite3. Based on the security tracker, this CVE is r