Wheezy update of libonig?

2017-05-25 Thread Raphael Hertzog
Hello Jörg, The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of libonig: https://security-tracker.debian.org/tracker/source-package/libonig Would you like to take care of this yourself? If yes, please follow the workflow we have defined her

Wheezy update of pngquant?

2017-05-25 Thread Raphael Hertzog
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of pngquant: https://security-tracker.debian.org/tracker/CVE-2016-5735 Would you like to take care of this yourself? If yes, please follow the workflow we have defined her

Re: testing bind9 for Wheezy LTS

2017-05-25 Thread Guido Günther
Hi, On Sat, May 20, 2017 at 04:57:52PM +0200, Thorsten Alteholz wrote: > Hi everybody, > > I uploaded version 9.8.4.dfsg.P1-6+nmu2+deb7u16 of bind9 to: > > https://people.debian.org/~alteholz/packages/wheezy-lts/bind9/amd64/ > > Please give it a try and tell me about any problems you met. I've

Patch proposal for CVE-2017-6960 in Wheezy (/Jessie)

2017-05-25 Thread Hugo Lefeuvre
Hi, I have prepared a patch for apng2gif 1.5. Testing did not reveal any problem, but I'm sure it can still be improved. Could anybody take a look at it ? Debdiff for wheezy is in attachment (a test package for wheezy is also available here[0]). This patch should also fix the issue in Jessie,

Re: testing bind9 for Wheezy LTS

2017-05-25 Thread Thorsten Alteholz
Hi Guido, On Thu, 25 May 2017, Guido Günther wrote: I've tested the package on a nameserver authoritive for some zones also using dnssec and on a caching configuration using IPv4 and IPv6 with no ill effects so far. thanks a lot for testing, your results are good to know. Thorsten

Re: Wheezy update of kde4libs?

2017-05-25 Thread Emilio Pozuelo Monfort
Hi Maxy, > > Would you like to take care of this yourself? > > Currently no, sorry. If you manage to work on this, please send me the > diff or the format-patch queue so I can record the upload in our vcs. I don't have a format-patch-formatted patch (:P), but please find attached the debdiff tha

Re: Firefox ESR large text file rendering problem

2017-05-25 Thread Emilio Pozuelo Monfort
On 08/05/17 09:05, Jari Ruusu wrote: > On 5/7/17, Marc SCHAEFER wrote: >> I cannot reproduce that problem on: >> >> $ cat /etc/debian_version >> 7.11 >> >> firefox 52.1.1-ESR, installed manually from >> http://ftp.mozilla.org/pub/firefox/releases/52.1.1esr/linux-x86_64/en-US/firefox-52.1.1esr.tar.

Re: Wheezy update of libonig?

2017-05-25 Thread Jörg Frings-Fürst
Hello Raphael, Hello LTS team, Am Donnerstag, den 25.05.2017, 12:40 +0200 schrieb Raphael Hertzog: > Hello Jörg, > > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of libonig: > https://security-tracker.debian.org/tracker/source-packag

Re: Firefox ESR large text file rendering problem

2017-05-25 Thread Jari Ruusu
On 5/25/17, Emilio Pozuelo Monfort wrote: > What about your 52 builds? Were those built against GTK+ 2 or 3? I have tried both. Also tried different compiler versions, different optimization levels, with and without jemalloc. firefox-52.1.2 compiled on Debian-7 "wheezy" GTK+ 3 ==> FAIL firefox-5

libonig/5.9.1-1+deb7u1 (CVE-2017-922[4-9])

2017-05-25 Thread Jörg Frings-Fürst
Hello Vincent, I have a bugfix release ready for a review. My changes: libonig (5.9.1-1+deb7u1) wheezy-security; urgency=high * New debian/patches/0500-CVE-2017-922[4-9].patch: - Cherrypicked from upstream to correct: + CVE-2017-9224 (Closes: #863312) + CVE-2017-9226 (Closes:

Re: libonig/5.9.1-1+deb7u1 (CVE-2017-922[4-9])

2017-05-25 Thread Vincent Cheng
Hi Jörg, On Thu, May 25, 2017 at 1:23 PM, Jörg Frings-Fürst wrote: > Hello Vincent, > > I have a bugfix release ready for a review. > > My changes: > > libonig (5.9.1-1+deb7u1) wheezy-security; urgency=high > > * New debian/patches/0500-CVE-2017-922[4-9].patch: > - Cherrypicked from upstrea