Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-20 Thread Yves-Alexis Perez
On dim., 2013-01-20 at 00:44 +0100, Daniel Pocock wrote: Thanks for confirming that It is possible that I bootstrapped 3.1.7 on an earlier Debian version than 3.1.8. E.g. Maybe 3.1.7 was bootstrapped on lenny and 3.1.8 on squeeze. This would mean different versions of autoconf were

Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-20 Thread Daniel Pocock
On 20/01/13 10:14, Yves-Alexis Perez wrote: On dim., 2013-01-20 at 00:44 +0100, Daniel Pocock wrote: Thanks for confirming that It is possible that I bootstrapped 3.1.7 on an earlier Debian version than 3.1.8. E.g. Maybe 3.1.7 was bootstrapped on lenny and 3.1.8 on squeeze. This would

Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-20 Thread Yves-Alexis Perez
On dim., 2013-01-20 at 10:40 +0100, Daniel Pocock wrote: In practice, people do stuff like this every day, but usually when compiling for a single platform where they can see the results themselves. I just don't know if there is some more pedantic approach to managing this type of risk for

Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-20 Thread Daniel Pocock
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 20/01/13 10:44, Yves-Alexis Perez wrote: On dim., 2013-01-20 at 10:40 +0100, Daniel Pocock wrote: In practice, people do stuff like this every day, but usually when compiling for a single platform where they can see the results themselves.

Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-20 Thread Yves-Alexis Perez
On dim., 2013-01-20 at 11:03 +0100, Daniel Pocock wrote: We're not interested in binary packages in Debian but you're indeed free to do that kind of QA work upstream. I'm not quite sure what you mean there... any package produced by dpkg-buildpackage is, by definition, a binary package,

Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-20 Thread Salvatore Bonaccorso
Hi On Sun, Jan 20, 2013 at 10:14:26AM +0100, Yves-Alexis Perez wrote: [...] If we need to be that pedantic about it to put something into squeeze (which may well be a good idea), then maybe we need to make the change without building and releasing any of the actual binaries, just release

Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-20 Thread Yves-Alexis Perez
On dim., 2013-01-20 at 13:07 +0100, Salvatore Bonaccorso wrote: So I have verified the following things: - The debdiff contains only the mentioned change (debdiff attached). - The patch is applied to /usr/share/ganglia-webfrontend/graph.php in the produced binary package

Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-20 Thread Salvatore Bonaccorso
Hi On Sun, Jan 20, 2013 at 06:15:30PM +0100, Yves-Alexis Perez wrote: On dim., 2013-01-20 at 13:07 +0100, Salvatore Bonaccorso wrote: So I have verified the following things: - The debdiff contains only the mentioned change (debdiff attached). - The patch is applied to

Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-19 Thread Daniel Pocock
On 19/01/13 21:52, Salvatore Bonaccorso wrote: Hi Daniel, hi all Ok let's try to reassume (I feel like there is some confusion ;-)) Squeeze currently has ganglia 3.1.7-1. So the updated package needs to be based on this. Usually introducing a new upstream version is not accepted for

Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-19 Thread Salvatore Bonaccorso
Hi Daniel, hi Yves-Alexis In short, [1] looks to be the only change needed for the security update. So the debdiff I posted should be okay. But I will leave it to Yves-Alexis (who is Debian Security Team member) which way to go. On Sat, Jan 19, 2013 at 10:15:00PM +0100, Daniel Pocock wrote: On

Bug#683584: [Pkg-monitoring-maintainers] ganglia update for Squeeze (CVE-2012-3448)

2013-01-19 Thread Daniel Pocock
On 20/01/13 00:02, Salvatore Bonaccorso wrote: Hi Daniel, hi Yves-Alexis In short, [1] looks to be the only change needed for the security update. So the debdiff I posted should be okay. But I will leave it to Yves-Alexis (who is Debian Security Team member) which way to go. On Sat, Jan