Re: Fwd: phpldapadmin_1.2.2-5+deb7u1_amd64.changes REJECTED

2017-07-11 Thread Chris Lamb
Hi Markus et. al., > > This is probably obvious to someone else, but I am rather confused by > > this rejection from security-master. > > we are currently having a difficult time when we try to upload arch:all > packages to wheezy-security. For instance we receive the following message: […] FYI

About the security issues affecting catdoc in Wheezy

2017-07-11 Thread Raphael Hertzog
Hello Martin, The Debian LTS team recently reviewed the security issue(s) affecting your package in Wheezy: https://security-tracker.debian.org/tracker/CVE-2017-0 We decided that we would not prepare a wheezy security update since the impact is low and unlikely to represent a serious issue in

Wheezy update of ipsec-tools?

2017-07-11 Thread Raphael Hertzog
Hello Christian and other ipsec-tools maintainers, The Debian LTS team would like to fix the security issue which is currently open in the Wheezy version of ipsec-tools: https://security-tracker.debian.org/tracker/CVE-2016-10396 Would you like to take care of this yourself? If yes, please follow

Re: Fwd: phpldapadmin_1.2.2-5+deb7u1_amd64.changes REJECTED

2017-07-11 Thread Markus Koschany
Am 11.07.2017 um 09:36 schrieb Chris Lamb: > Hi Markus et. al., > >>> This is probably obvious to someone else, but I am rather confused by >>> this rejection from security-master. >> >> we are currently having a difficult time when we try to upload arch:all >> packages to wheezy-security. For ins

Re: unattended upgrades don't work in wheezy

2017-07-11 Thread Matus UHLAR - fantomas
On 09.07.17 15:41, Chris Lamb wrote: Is this https://bugs.debian.org/762965 ? I don't think so. That bug is caused by someone making changes to config file ("For extra security i have added the parameter n=wheezy.") Ah okay, thanks. Can you file a new bug against unattended-upgrades with a "

Wheezy update of lame?

2017-07-11 Thread Raphael Hertzog
Dear Fabian and other maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of lame: https://security-tracker.debian.org/tracker/CVE-2017-9872 https://security-tracker.debian.org/tracker/CVE-2017-9871 https://security-tracker.debian

Wheezy update of lucene-solr?

2017-07-11 Thread Raphael Hertzog
Dear maintainers, The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of lucene-solr: https://security-tracker.debian.org/tracker/CVE-2017-3163 Would you like to take care of this yourself? I noticed that lucene-solr is seriously out-of-date c

Wheezy update of swftools?

2017-07-11 Thread Raphael Hertzog
Hello Christian, The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of swftools: https://security-tracker.debian.org/tracker/source-package/swftools Note that the security team marked a bunch of issues as unimportant but you are free to fix th

Re: Wheezy update of ncurses?

2017-07-11 Thread Roberto C . Sánchez
On Sun, Jul 09, 2017 at 03:14:33PM +0100, Chris Lamb wrote: > Dear maintainer(s), > > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of ncurses: > https://security-tracker.debian.org/tracker/source-package/ncurses > All the open ncurses

Re: [SECURITY] [DLA 997-1] libffi security update

2017-07-11 Thread Joachim Ernst
On Wed, Jun 21, 2017 at 11:52:37AM -0300, Lucas Kanashiro wrote: > Package: libffi > Version: 3.0.10-3+deb7u1 > CVE ID : CVE-2017-1000376 > > libffi requests an executable stack allowing attackers to more easily trigger > arbitrary code execution by overwriting the stack. P

Re: Wheezy update of ncurses?

2017-07-11 Thread Sven Joachim
On 2017-07-11 10:17 -0400, Roberto C. Sánchez wrote: > On Sun, Jul 09, 2017 at 03:14:33PM +0100, Chris Lamb wrote: >> The Debian LTS team would like to fix the security issues which are >> currently open in the Wheezy version of ncurses: >> https://security-tracker.debian.org/tracker/source-packag

testing bind9 for Wheezy LTS

2017-07-11 Thread Thorsten Alteholz
Hi everybody, I uploaded version 9.8.4.dfsg.P1-6+nmu2+deb7u17 of bind9 to: https://people.debian.org/~alteholz/packages/wheezy-lts/bind9/amd64/ Please give it a try and tell me about any problems you met. It would be nice if you could especially test TSIG. Thanks! Thorsten * CVE-2017-3142