Bug#850014: unblock: libgit2/0.24.5-1

2017-01-02 Thread Russell Sim
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package libgit2 The main reasons is that i messed up the packaging of version 0.24.2-1, and have flagged CVE-2016-8568 [0] as being fixed which is untrue. This package both

Bug#850003: jessie-pu: package python-cryptography/0.6.1-1+deb8u1

2017-01-02 Thread Tristan Seligmann
Package: release.debian.org Severity: normal Tags: jessie User: release.debian@packages.debian.org Usertags: pu Backport the fix for CVE-2016-9243 which was deemed not severe enough for a DSA. I've attached a full debdiff, the patch is quite small and self-contained, although I needed another

NEW changes in stable-new

2017-01-02 Thread Debian FTP Masters
Processing changes file: linux_3.16.39-1_armel.changes ACCEPT

NEW changes in stable-new

2017-01-02 Thread Debian FTP Masters
Processing changes file: linux_3.16.39-1_armhf.changes ACCEPT

NEW changes in stable-new

2017-01-02 Thread Debian FTP Masters
Processing changes file: linux_3.16.39-1_i386.changes ACCEPT

NEW changes in stable-new

2017-01-02 Thread Debian FTP Masters
Processing changes file: linux_3.16.39-1_amd64.changes ACCEPT

NEW changes in stable-new

2017-01-02 Thread Debian FTP Masters
Processing changes file: cairo_1.14.0-2.1+deb8u2_mips.changes ACCEPT

NEW changes in stable-new

2017-01-02 Thread Debian FTP Masters
Processing changes file: cairo_1.14.0-2.1+deb8u2_armel.changes ACCEPT Processing changes file: cairo_1.14.0-2.1+deb8u2_armhf.changes ACCEPT Processing changes file: cairo_1.14.0-2.1+deb8u2_mipsel.changes ACCEPT Processing changes file: cairo_1.14.0-2.1+deb8u2_ppc64el.changes ACCEPT Processi

NEW changes in stable-new

2017-01-02 Thread Debian FTP Masters
Processing changes file: cairo_1.14.0-2.1+deb8u2_amd64.changes ACCEPT Processing changes file: cairo_1.14.0-2.1+deb8u2_arm64.changes ACCEPT Processing changes file: cairo_1.14.0-2.1+deb8u2_i386.changes ACCEPT Processing changes file: cairo_1.14.0-2.1+deb8u2_s390x.changes ACCEPT Processing c

NEW changes in stable-new

2017-01-02 Thread Debian FTP Masters
Processing changes file: cairo_1.14.0-2.1+deb8u2_powerpc.changes ACCEPT Processing changes file: libfcgi-perl_0.77-1+deb8u1_amd64.changes ACCEPT Processing changes file: libfcgi-perl_0.77-1+deb8u1_arm64.changes ACCEPT Processing changes file: libfcgi-perl_0.77-1+deb8u1_armel.changes ACCEPT

Bug#849967: jessie-pu: package exim4/4.84.2-2+deb8u3

2017-01-02 Thread Andreas Metzler
Package: release.debian.org Severity: normal Tags: jessie User: release.debian@packages.debian.org Usertags: pu Hello, I (and Heiko from exim upstream) would like to fix #845569 in jessie. sid/testing already include the fix, it was part of 4.88~RC6. The issue is a memleak in the GnuTLS code

NEW changes in stable-new

2017-01-02 Thread Debian FTP Masters
Processing changes file: cairo_1.14.0-2.1+deb8u2_allonly.changes ACCEPT Processing changes file: libfcgi-perl_0.77-1+deb8u1_allonly.changes ACCEPT Processing changes file: libgd2_2.1.0-5+deb8u8_allonly.changes ACCEPT Processing changes file: libgd2_2.1.0-5+deb8u8_amd64.changes ACCEPT Proces

Bug#849438: jessie-pu: package libfcgi-perl/0.77-1+deb8u1

2017-01-02 Thread Adam D. Barratt
Control: tags -1 + pending Hi, On Sat, 2016-12-31 at 19:53 +0100, Salvatore Bonaccorso wrote: > Hi Adam, > > On Sat, Dec 31, 2016 at 05:11:25PM +, Adam D. Barratt wrote: > > Control: tags -1 + confirmed > > > > On Tue, 2016-12-27 at 08:17 +0100, Salvatore Bonaccorso wrote: > > > Moritz Mühl

Bug#849467: jessie-pu: package hplip/3.14.6-1+deb8u1

2017-01-02 Thread Adam D. Barratt
On Sun, 2017-01-01 at 11:38 +0100, Didier 'OdyX' Raboud wrote: > Le samedi, 31 décembre 2016, 17.10:09 h CET Adam D. Barratt a écrit : > > Control: tags -1 + confirmed > > > > On Tue, 2016-12-27 at 14:18 +0100, Didier 'OdyX' Raboud wrote: > > > I'd like to get CVE-2015-0839 fixed in jessie, it's a

Processed: Re: Bug#849438: jessie-pu: package libfcgi-perl/0.77-1+deb8u1

2017-01-02 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + pending Bug #849438 [release.debian.org] jessie-pu: package libfcgi-perl/0.77-1+deb8u1 Added tag(s) pending. -- 849438: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=849438 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Processed: Re: Bug#849725: jessie-pu cairo/1.14.0-2.1+deb8u2

2017-01-02 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + pending Bug #849725 [release.debian.org] jessie-pu: package cairo/1.14.0-2.1+deb8u2 Added tag(s) pending. -- 849725: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=849725 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#849725: jessie-pu cairo/1.14.0-2.1+deb8u2

2017-01-02 Thread Adam D. Barratt
Control: tags -1 + pending Hi, On Sat, 2016-12-31 at 20:08 +0100, Salvatore Bonaccorso wrote: > Hi Adam, > > On Sat, Dec 31, 2016 at 04:58:46PM +, Adam D. Barratt wrote: > > Control: tags -1 + confirmed > > > > On Fri, 2016-12-30 at 07:52 +0100, Salvatore Bonaccorso wrote: > > > src:cairo i

Bug#849962: jessie-pu: package libpng/1.2.50-2+deb8u3

2017-01-02 Thread Gianfranco Costamagna
Package: release.debian.org User: release.debian@packages.debian.org Usertags: pu Tags: jessie Severity: normal CVE-2016-10087 is not worth a DSA, Security Team asked for a point release update. diff -Nru libpng-1.2.50/debian/changelog libpng-1.2.50/debian/changelog --- libpng-1.2.50/debian/

Re: embedding openssl source in sslcan

2017-01-02 Thread Christian Seiler
Hi, Am 2. Januar 2017 11:35:30 MEZ, schrieb Thijs Kinkhorst : >On Fri, December 23, 2016 18:53, Moritz Mühlenhoff wrote: >> Sebastian Andrzej Siewior schrieb: >> >> Please use t...@security.debian.org if you want to reach the security >> team, not debian-security@ldo. >> >>> tl;dr: Has anyone a

Bug#849218: transition: imagemagick

2017-01-02 Thread Bastien ROUCARIÈS
control: affect 844357 src:zbar control: block -1 by 844357 Le jeudi 29 décembre 2016, 16:37:43 CET Emilio Pozuelo Monfort a écrit : > Control: tags -1 confirmed > > The break was in 6.9.2-10 released in mid 2015. This is moreover only two > > version latter than current jessie and I believe it w

Re: embedding openssl source in sslcan

2017-01-02 Thread Thijs Kinkhorst
On Fri, December 23, 2016 18:53, Moritz Mühlenhoff wrote: > Sebastian Andrzej Siewior schrieb: > > Please use t...@security.debian.org if you want to reach the security > team, not debian-security@ldo. > >> tl;dr: Has anyone a problem if sslscan embeds openssl 1.0.2 in its >> source? > > That's f

Re: Bug#822604: scanmem: depends on gksu which is deprecated

2017-01-02 Thread Sebastian Parschauer
On 02.01.2017 10:48, Vincent Bernat wrote: >> I don't know what else I should do. Please upload! > > Emilio may be currently busy. You have better chance of getting someone > else helping with the upload if you provide a link to a .dsc so that > people don't have to look at where the original tarb

Re: Bug#822604: scanmem: depends on gksu which is deprecated

2017-01-02 Thread Vincent Bernat
❦ 2 janvier 2017 10:12 +0100, Sebastian Parschauer  : >> Please upload! TIA > > We are reaching the new package submission deadline for Debian Stretch > 2017-01-05 very soon. > > More than 5 years old version 0.13 which is full of bugs and insecure > will be in Stretch if nobody uploads my new p

Re: Bug#822604: scanmem: depends on gksu which is deprecated

2017-01-02 Thread Sebastian Parschauer
On 17.12.2016 20:18, Sebastian Parschauer wrote: > Please upload! TIA We are reaching the new package submission deadline for Debian Stretch 2017-01-05 very soon. More than 5 years old version 0.13 which is full of bugs and insecure will be in Stretch if nobody uploads my new package from: https