zynaddsubfx_3.0.5-1_amd64.changes is NEW

2019-07-24 Thread Debian FTP Masters
binary:zynaddsubfx-lv2 is NEW. binary:zynaddsubfx-vst is NEW. binary:zynaddsubfx-lv2 is NEW. binary:zynaddsubfx-vst is NEW. Your package has been put into the NEW queue, which requires manual action from the ftpteam to process. The upload was otherwise valid (it had a good OpenPGP signature and fi

Processing of zynaddsubfx_3.0.5-1_amd64.changes

2019-07-24 Thread Debian FTP Masters
zynaddsubfx_3.0.5-1_amd64.changes uploaded successfully to localhost along with the files: zynaddsubfx_3.0.5-1.dsc zynaddsubfx_3.0.5.orig.tar.bz2 zynaddsubfx_3.0.5-1.debian.tar.xz zynaddsubfx-data_3.0.5-1_all.deb zynaddsubfx-dbgsym_3.0.5-1_amd64.deb zynaddsubfx-dssi-dbgsym_3.0.5-1_amd64

Re: Update of zynaddsubfx

2019-07-24 Thread Mattia Rizzolo
On Wed, Jul 24, 2019 at 08:16:13PM +0200, Reiner Herrmann wrote: > You can find another MR for that at [0]. Thank you! I've now uploaded it, and will land to NEW. It will need another source only upload at some point to have it migrate to buster, feel free to poke me if nobody comes aroud to it (

Re: Update of zynaddsubfx

2019-07-24 Thread Reiner Herrmann
Hi Mattia, On Wed, Jul 24, 2019 at 02:35:52PM +0200, Mattia Rizzolo wrote: > > I'm going to review and merge them! And upload to sid as needed :) > > > I also noticed that the LV2/VST plugins are now (in the unreleased git > > branch [3]) installed as part of the main zynaddsubfx binary package

Bug#932241: patch for CVE-2019-13615

2019-07-24 Thread Christopher Wellons
This patch is just "git diff d559b0d..534dfdb" on the upstream libebml repository, refreshed with quilt. It's an amalgamation of a series of related changes that fix this bug. With this patch, VLC no longer segfaults reading heap-over-flow.mp4 from the upstream bugtracker. diff --git a/src/EbmlE

Processed: retitle 932241 to libebml: CVE-2019-13615

2019-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 932241 libebml: CVE-2019-13615 Bug #932241 [src:libebml] vlc: CVE-2019-13615 Changed Bug title to 'libebml: CVE-2019-13615' from 'vlc: CVE-2019-13615'. > thanks Stopping processing here. Please contact me if you need assistance. -- 93224

Processed: notfound 932241 in 3.0.7.1-1, notfound 932241 in 3.0.7.1-2, notfound 932241 in 3.0.7-0+deb9u1 ...

2019-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > notfound 932241 3.0.7.1-1 Bug #932241 [src:vlc] vlc: CVE-2019-13615 No longer marked as found in versions vlc/3.0.7.1-1. > notfound 932241 3.0.7.1-2 Bug #932241 [src:vlc] vlc: CVE-2019-13615 No longer marked as found in versions vlc/3.0.7.1-2. > n

Processed: reassign 932241 to src:libebml, fixed 932241 in 1.3.6-1

2019-07-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 932241 src:libebml 1.3.4-1 Bug #932241 [src:vlc] vlc: CVE-2019-13615 Bug reassigned from package 'src:vlc' to 'src:libebml'. Ignoring request to alter found versions of bug #932241 to the same values previously set Ignoring request to al

Bug#932241: vlc: CVE-2019-13615

2019-07-24 Thread Jonathan Brandmeyer
Friendly heads-up: Upstream is tracking this at https://trac.videolan.org/vlc/ticket/22474 They believe that the root cause is in libebml rather than vlc, and a newer release of this library fixes the bug. HTH,

Re: Update of zynaddsubfx

2019-07-24 Thread Mattia Rizzolo
Hi! On Tue, Jul 23, 2019 at 12:29:14AM +0200, Reiner Herrmann wrote: > I opened a few merge requests on salsa against zynaddsubfx [0][1][2]. > They update the package to upstream version 3.0.5 and contain a few > other smaller changes. > Can someone please review the changes and merge them? > And