minor issues (wavpack)

2019-07-22 Thread Brian May
I am a bit unclear when we should be some issues, and when we should be marking them as no-DSA (or similar). For example, webpack was three issues: - CVE-2019-1010315: divide by zero - CVE-2019-1010317: use of uninitialized memory. - CVE-2019-1010319: use of uninitialized memory. All three issue

Re: Advice for building tomcat8 on jessie?

2019-07-22 Thread Abhijith PA
Hello. tomcat8 is FTBFS in jessie. I think the culprit is CVE-2017-5647 patch which makes TestSendFile to fail. I tried with a latest upstream change of TestSendfile but it is still failing. I like to get help on this one. --abhijith

Re: minor issues (wavpack)

2019-07-22 Thread Abhijith PA
Hi, On 22/07/19 1:13 pm, Brian May wrote: > I am a bit unclear when we should be some issues, and when we should be > marking them as no-DSA (or similar). > > For example, webpack was three issues: > > - CVE-2019-1010315: divide by zero > - CVE-2019-1010317: use of uninitialized memory. > - CVE-

(semi-)automatic unclaim of packages with more than 2 weeks of inactivity

2019-07-22 Thread Holger Levsen
hi, today I unclaimed these packages: for LTS: -cfengine3 (Mike Gabriel) -glib2.0 (Mike Gabriel) -imagemagick (Mike Gabriel) -tomcat8 (Abhijith PA) and none for eLTS. -- tschau, Holger --- holg

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity

2019-07-22 Thread Roberto C . Sánchez
On Mon, Jul 22, 2019 at 02:36:36PM +, Holger Levsen wrote: > hi, > > today I unclaimed these packages: > > for LTS: > -cfengine3 (Mike Gabriel) > -glib2.0 (Mike Gabriel) > -imagemagick (Mike Gabriel) > -tomcat8 (Abhijith PA) > To be fair, Abhijith did just today send a request for assistance

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity

2019-07-22 Thread Holger Levsen
On Mon, Jul 22, 2019 at 11:48:20AM -0400, Roberto C. Sánchez wrote: > To be fair, Abhijith did just today send a request for assistance with > the FBTFS problem on tomcat8. I'd seen this, just that me unclaiming packages is not ment to be fair or unfair, but rather just a means to get probably s

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity

2019-07-22 Thread Roberto C . Sánchez
On Mon, Jul 22, 2019 at 04:41:11PM +, Holger Levsen wrote: > On Mon, Jul 22, 2019 at 11:48:20AM -0400, Roberto C. Sánchez wrote: > > To be fair, Abhijith did just today send a request for assistance with > > the FBTFS problem on tomcat8. > > I'd seen this, just that me unclaiming packages is

Re: libsdl2-image security issues in testing

2019-07-22 Thread Felix Geyer
Hi Hugo, On 21.07.19 18:30, Hugo Lefeuvre wrote: Dear libsdl2-image maintainers, I have prepared a jessie (LTS) update addressing libsdl2-image's current security issues. I will coordinate with the security team to possibly fix them in a future stretch/buster point update. Are you planning to

Re: libsdl2-image security issues in testing

2019-07-22 Thread Hugo Lefeuvre
Hi Felix, (CC-ing #932754 which tracks this issue) > > I have prepared a jessie (LTS) update addressing libsdl2-image's current > > security issues. I will coordinate with the security team to possibly fix > > them in a future stretch/buster point update. > > > > Are you planning to address thes