LTS report for November 2019 - Abhijith PA

2019-11-29 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 November was my 21st month as a Debian LTS paid contributor. I was assigned 8 hours and I spent all of them for the following: * libssh2: Fixed CVE-2019-17498, tested and uploaded. DLA[1] * slurm-lnll: Backported a huge part of CVE-2019-12838, CV

Jessie update of ssvnc?

2019-11-29 Thread Mike Gabriel
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Jessie version of ssvnc: https://security-tracker.debian.org/tracker/CVE-2018-20020 https://security-tracker.debian.org/tracker/CVE-2018-20021 https://security-tracker.debian.org/tracker/C

Re: RFS: 389-ds-base

2019-11-29 Thread Mike Gabriel
Hi Utkarsh, On Mo 25 Nov 2019 02:11:35 CET, Utkarsh Gupta wrote: Hey, I have fixed CVE-2019-14824 for 389-ds-base and uploaded the same to mentors.d.net. The relevant .dsc could be found at [1]. Requesting to upload the same on my behalf. Attaching the DLA file for the same. Also, sent a pa

Re: RFS: 389-ds-base

2019-11-29 Thread Mike Gabriel
Hi, On Mo 25 Nov 2019 02:11:35 CET, Utkarsh Gupta wrote: Hey, I have fixed CVE-2019-14824 for 389-ds-base and uploaded the same to mentors.d.net. The relevant .dsc could be found at [1]. Requesting to upload the same on my behalf. Attaching the DLA file for the same. Also, sent a patch for

Re: RFS: tnef

2019-11-29 Thread Mike Gabriel
Hi, On Mo 25 Nov 2019 06:00:51 CET, Utkarsh Gupta wrote: Hey, I have fixed CVE-2019-18849 for tnef and uploaded the same to mentors.d.net. The relevant .dsc could be found at [1]. Requesting to upload the same on my behalf. Attaching the DLA file for the same. Also, sent a patch for Stretch

Re: RFS: 389-ds-base

2019-11-29 Thread Holger Levsen
Hi Mike, Utkarsh, On Fri, Nov 29, 2019 at 12:24:34PM +, Mike Gabriel wrote: > Sorry for the delay. Looking into it right now. > Mike (with LTS frontdesk hat on) thanks a lot for this and the uploads, Mike! Utkarsh has pinged me privately last night and thus it was on my list for today, but I'

Re: RFS: 389-ds-base

2019-11-29 Thread Mike Gabriel
Hi Holger, On Fr 29 Nov 2019 13:46:23 CET, Holger Levsen wrote: Hi Mike, Utkarsh, On Fri, Nov 29, 2019 at 12:24:34PM +, Mike Gabriel wrote: Sorry for the delay. Looking into it right now. Mike (with LTS frontdesk hat on) thanks a lot for this and the uploads, Mike! Utkarsh has pinged m

Jessie update of libjackson-json-java?

2019-11-29 Thread Mike Gabriel
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Jessie version of libjackson-json-java: https://security-tracker.debian.org/tracker/CVE-2019-10172 Would you like to take care of this yourself? If yes, please follow the workflow we hav

Jessie update of asterisk?

2019-11-29 Thread Mike Gabriel
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Jessie version of asterisk: https://security-tracker.debian.org/tracker/CVE-2019-18790 https://security-tracker.debian.org/tracker/CVE-2019-18610 Would you like to take care of this yours

Jessie update of proftpd-dfsg?

2019-11-29 Thread Mike Gabriel
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Jessie version of proftpd-dfsg: https://security-tracker.debian.org/tracker/CVE-2019-19269 https://security-tracker.debian.org/tracker/CVE-2019-19270 https://security-tracker.debian.org/tr

Re: RFT: OpenJDK 7 7u241-2.6.20-1~deb8u1

2019-11-29 Thread Roberto C . Sánchez
On Tue, Nov 26, 2019 at 04:01:44PM +0100, Markus Koschany wrote: > Hello, > > I have uploaded a new version of OpenJDK 7 to > > https://people.debian.org/~apo/openjdk7/amd64/ > > including all binaries and sources, along with a signed .changes file. > > Please let me know if you find any regres

Re: RFT: OpenJDK 7 7u241-2.6.20-1~deb8u1

2019-11-29 Thread Roberto C . Sánchez
On Fri, Nov 29, 2019 at 10:48:06AM -0500, Roberto C. Sánchez wrote: > > I still need to work on tweaking the scripts under debian/tests and will > provide a further update when I have something that at least somewhat > works. > I have been able to get a "working" autopkgtest such that the test ex