Re: DLA 773-1 and DLA 773-2

2017-01-10 Thread Thomas Martin
Thanks to both of you Chris and Guido! Cheers! Thomas 2017-01-09 23:16 GMT+01:00 Chris Lamb : > Guido Günther wrote: > >> I think the rule (as I understood it) is "every change to *-security" >> gets a D{S,L}A so people know why things are changing in these suites. > > Yeah, that makes sense. I w

Re: DLA 773-1 and DLA 773-2

2017-01-10 Thread Chris Lamb
Hi Thomas, > Thanks to both of you Chris and Guido! No problem. Packages available now and I've just announced DLA 773-4. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

nvidia-graphics-drivers 304.134 proposed packages for wheezy-lts

2017-01-10 Thread Andreas Beckmann
Hi, I've prepared a new upstream release of the proprietary nvidia graphics driver for wheezy-lts. This will fix several security bugs: * New upstream legacy 304xx branch release 304.134 (2016-12-14). * Fixed CVE-2016-8826. (Closes: #848195) * New upstream legacy 304xx branch release 304

Re: nvidia-graphics-drivers 304.134 proposed packages for wheezy-lts

2017-01-10 Thread Chris Lamb
Andreas Beckmann wrote: > I've prepared a new upstream release of the proprietary nvidia graphics > driver for wheezy-lts. This will fix several security bugs: Do you have a debdiff handy...? (Or, better still, diffoscope output.) Regards, -- ,''`. : :' : Chris Lamb `. `

Re: wheezy update for libav

2017-01-10 Thread Diego Biurrun
On Fri, Jan 06, 2017 at 11:32:49AM +0100, Hugo Lefeuvre wrote: > > I've had a look at the new CVEs reported for libav. I managed to > reproduce CVE-2016-98{21,22} (avconv crashes with segfault), but > cherry picking the fix[0,1,2] for these issues doesn't seem to fix > the problem. You were missi

Re: Wheezy update of ikiwiki?

2017-01-10 Thread Simon McVittie
On Fri, 23 Dec 2016 at 23:39:09 +, Simon McVittie wrote: > On Thu, 22 Dec 2016 at 23:09:38 +0100, Ola Lundqvist wrote: > > the Debian LTS team would like to fix the security issues which are > > currently open in the Wheezy version of ikiwiki: > > https://security-tracker.debian.org/tracker/CVE