Re: wheezy update for libav

2016-11-03 Thread Hugo Lefeuvre
Hi Diego, > I looked into backporting the fixes for > > https://lists.debian.org/debian-lts/2016/09/msg00211.html > > that the Mozilla people complained about from the 9 release branch to the > 0.8 release branch. It's entirely nontrivial since the commits that fix > the issue constitute a major

Debian LTS Report for October 2016

2016-11-03 Thread Hugo Lefeuvre
Hi, October 2016 was my second month as a payed Debian LTS contributor. I was allocated 12 hours. I have spent 12 hours doing the following tasks: * Test and upload a security update for libav (0.8.18-0+deb7u1). Discussion with upstream to get more point releases. DLA: 644-1 Closed CVEs: C

Re: CVE-2016-9013 / django-python

2016-11-03 Thread Ben Hutchings
On Fri, 2016-11-04 at 08:31 +1100, Brian May wrote: > Hello All, > > Looking at CVE-2016-9013 for django-python in wheezy-security, I see > that: > > * It only occurs if you run the tests on an Oracle server. > * The window for exploitation is reduced if you don't use the --keepdb >   option. Not

Re: linux-image-3.2.0-4-486

2016-11-03 Thread Ben Hutchings
On Wed, 2016-11-02 at 22:25 +0100, Miroslav Skoric wrote: > Ten days ago I upgraded one of my older PCs running wheezy from kernel  > 3.2.81-2 to 3.2.82-1 and soon after I realized that the system started  > to "freeze" a couple of minutes after booting. Does that happen while you are actively usi

Re: CVE-2016-9013 / django-python

2016-11-03 Thread Brian May
Ben Hutchings writes: > I'm not convinced this even warrants a security advisory. Same here. So maybe I should just mark it no-dsa? Possibly confirming with the security-team first to see if I should also marke Jessie no-dsa too. -- Brian May