Re: What to do with jbig2dec in wheezy and jessie

2017-03-23 Thread Moritz Mühlenhoff
On Tue, Mar 21, 2017 at 10:53:05AM +0100, Raphael Hertzog wrote: > Hello Moritz, > > On Sun, 12 Mar 2017, Moritz Mühlenhoff wrote: > > > So as long as we ensure that we don't break Ghostscript and MuPDF I think > > > we are good enough. > > > > > > Shall I go ahead and prepare some test packages?

Re: What to do with jbig2dec in wheezy and jessie

2017-03-23 Thread Raphael Hertzog
Hello Moritz, On Thu, 23 Mar 2017, Moritz Mühlenhoff wrote: > > Please find packages for Jessie here: > > https://people.debian.org/~hertzog/packages/jbig2dec_0.13-4~deb8u1_amd64.changes [...] > > Can I upload the jessie packages to security-master? > > Thanks, please upload. Done. Uploading to

Fwd: [Announce] Samba 4.6.1, 4.5.7 and 4.4.12 Security Releases Available for Download

2017-03-23 Thread Mathieu Parent
Hi, Today samba has released a security fix for a symlink race (leading to information disclosure). Salvatore will take care of the jessie upload, I have uploaded for sid, but we have not done anything on the wheezy side. See attached the backported patches for 3.6 (those are from the samba bugz

Re: Wheezy update of git?

2017-03-23 Thread Raphael Hertzog
Hi, On Tue, 21 Mar 2017, Raphael Hertzog wrote: > I tried to checkout https://github.com/njhartwell/pw3nage while having > bash-completion loaded and with a PS1 containing $(__git_ps1 2>/dev/null) > or $(__git_ps1 " (%s)") and was unable to get any code execution. > > I'm not sure when the vulner

Re: [Announce] Samba 4.6.1, 4.5.7 and 4.4.12 Security Releases Available for Download

2017-03-23 Thread Ola Lundqvist
Hi Mathieu Thank you for this information. The LTS team will handle this. If nobody else step up I will do it myself. For the LTS team: I will add this to the dla-needed.txt file later today but feel free to add that and claim yourself to this update. Best regards // Ola On 23 March 2017 at 11

request for testing: php5 security update

2017-03-23 Thread Markus Koschany
Hi, I have prepared a security update for php5 which addresses CVE-2016-7478 and CVE-2016-7479. Please give it a try and tell me about any issues you encounter. Prebuilt binary packages for amd64 and the debdiff, if you prefer to build from source, are available at: https://people.debian.org/~apo

Wheezy update of libvpx?

2017-03-23 Thread Ola Lundqvist
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of libvpx: https://security-tracker.debian.org/tracker/CVE-2017-0393 https://security-tracker.debian.org/tracker/CVE-2017-6711 Would you like to take care of this you