Re: CVE-2019-14866

2019-11-05 Thread Ola Lundqvist
Hi Ok, thank you. Then I'll use the version Thomas used for Debian old and oldold stable. I'll use that as I have tested it already and it is easier to read for someone wanting to compare the difference compared to an older version. Best regards // Ola On Mon, 4 Nov 2019 at 21:25, Sergey Poznya

LTS report for October 2019 - Abhijith PA

2019-11-05 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 October was my 20th month as a Debian LTS paid contributor. I had 14 hours assigned. Out of which I spent 8 hours and gave back rest to the pool. * novnc: Fixed CVE-2017-18635, tested and uploaded. DLA[1] * libpcap: Fixed CVE-2019-15165, tested a

Re: Security issues in standards (ruby-openid / CVE-2019-11027)

2019-11-05 Thread Brian May
Utkarsh Gupta writes: > I am not quite sure about what should we do here because the update (DLA > 1956-1) doesn't quite fix the CVE completely and also brings some login > problems as reported in #125. > Because for now, #121 + #126 = actual CVE fix. But the login problem > remains. I guess we