Re: lbglib-json in Jessie

2018-07-09 Thread Chris Lamb
Allin, > The upstream software in question is called json-glib, and the > Debian packages are libjson-glib*. (The names have gone a little > adrift up-thread.) Nothing has gone adrift. The Debian source package is called json-glib, the binary packages are called libjson-glib* (and gir1.2-json-*

Re: lbglib-json in Jessie

2018-07-09 Thread Allin Cottrell
On Mon, 9 Jul 2018, Chris Lamb wrote: Allin, The upstream software in question is called json-glib, and the Debian packages are libjson-glib*. (The names have gone a little adrift up-thread.) Nothing has gone adrift. Hmm, "lbglib-json"? The Debian source package is called json-glib, the b

Re: jetty CVE triage: jetty8 ignored?

2018-07-09 Thread Ola Lundqvist
Hi Sebastien and others I have checked a few of the CVEs from 2009 and my conclusion is that this is not important enough for LTS work. CVE-2009-5045 to CVE-2009-5049 advisory sent by jetty telling that jetty 6 and 7 are affected. The version in jessie is of a version that is fixed. As jetty 8 di