Processed: Re: Bug#849698: jessie-pu: package python-crypto/2.6.1-5+deb8u1

2017-01-01 Thread Debian Bug Tracking System
Processing control commands: > tags -1 - moreinfo Bug #849698 [release.debian.org] jessie-pu: package python-crypto/2.6.1-5+deb8u1 Removed tag(s) moreinfo. -- 849698: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=849698 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#849698: jessie-pu: package python-crypto/2.6.1-5+deb8u1

2017-01-01 Thread Sebastian Ramacher
Control: tags -1 - moreinfo Hi On 2016-12-31 17:03:32, Adam D. Barratt wrote: > Control: tags -1 + moreinfo > > On Thu, 2016-12-29 at 23:15 +0100, Sebastian Ramacher wrote: > > I'd like to fix CVE-2013-7459 (#849495) in jessie via the next point > > release. > > The issue was marked as no-dsa.

Bug#849869: jessie-pu: package unrtf/0.21.5-3

2017-01-01 Thread Willi Mann
Package: release.debian.org Severity: normal Tags: jessie User: release.debian@packages.debian.org Usertags: pu As per request of the security team, I intend to upload a security fix (CVE-2016-10091) of the unrtf package for the next jessie point release. The changelog is: unrtf (0.21.5-3+de

Bug#849865: jessie-pu: package postgresql-common/165+deb8u2

2017-01-01 Thread Christoph Berg
Package: release.debian.org Severity: normal Tags: jessie User: release.debian@packages.debian.org Usertags: pu Hi, I would like to upload postgresql-common/165+deb8u2 with the diff quoted below to jessie. It's fixing a data-loss bug, and a security issue. The issues are already addresses in

Re: [Pkg-openssl-devel] embedding openssl source in sslcan

2017-01-01 Thread Kurt Roeckx
On Sun, Jan 01, 2017 at 04:37:48PM +0100, Raphael Hertzog wrote: > On Sat, 31 Dec 2016, Julien Cristau wrote: > > On Thu, Dec 22, 2016 at 13:37:11 +0100, Sebastian Andrzej Siewior wrote: > > > > > tl;dr: Has anyone a problem if sslscan embeds openssl 1.0.2 in its > > > source? > > > > > > sslscan

Re: embedding openssl source in sslcan

2017-01-01 Thread Raphael Hertzog
On Sat, 31 Dec 2016, Julien Cristau wrote: > On Thu, Dec 22, 2016 at 13:37:11 +0100, Sebastian Andrzej Siewior wrote: > > > tl;dr: Has anyone a problem if sslscan embeds openssl 1.0.2 in its > > source? > > > > sslscan [0] as packaged in Debian currently relies on external libssl as > > provided

Bug#849855: unblock: unrtf/0.21.9-clean-3

2017-01-01 Thread Willi Mann
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please lower the testing migration delay for package unrtf. It fixes CVE-2016-10091 (buffer overflow). Debdiff attached. Note that the changes to import-orig.sh in the debdiff can be ignor

Bug#849467: jessie-pu: package hplip/3.14.6-1+deb8u1

2017-01-01 Thread Didier 'OdyX' Raboud
Le samedi, 31 décembre 2016, 17.10:09 h CET Adam D. Barratt a écrit : > Control: tags -1 + confirmed > > On Tue, 2016-12-27 at 14:18 +0100, Didier 'OdyX' Raboud wrote: > > I'd like to get CVE-2015-0839 fixed in jessie, it's a no-DSA issue, and > > security team members suggested to get it fixed th

Re: Let autopkgtests be gating for testing migration in Buster: heads-up and brain-dump

2017-01-01 Thread Martin Pitt
Hello all, Julien Cristau [2016-12-31 17:45 +0100]: > > > 2b) let britney generate a list of tests it would like to perform > > Is 2b really necessary? I'm not sure why we would need that. > > > Or to be more correct, I'm not sure we would *want* britney to be able > to (or have to) do that. I