Bug#840546: CVE-2016-7966 kdepimlibs jessie

2016-10-20 Thread Sandro Knauß
Hey Moritz, ping. Are there anything missing before rolling out the patch inside jessie- security? Can I help somehow / are you need input from my side? Regards, sandro -- Am Freitag, 14. Oktober 2016, 21:23:45 CEST schrieb Moritz Muehlenhoff: > On Fri, Oct 14, 2016 at 08:23:04PM +0200,

Bug#840546: CVE-2016-7966 kdepimlibs jessie

2016-10-14 Thread Salvatore Bonaccorso
Hi Sandro, On Fri, Oct 14, 2016 at 10:56:00PM +0200, Sandro Knauß wrote: > Hi, > > now I'm fully confused - you said on IRC, I should better create a deb8u2 > ontop. Well I created now the debdiff for a deb8u2. > > So you can decide what is the best way for the sec team and what version >

Bug#840546: CVE-2016-7966 kdepimlibs jessie

2016-10-14 Thread Sandro Knauß
Hi, now I'm fully confused - you said on IRC, I should better create a deb8u2 ontop. Well I created now the debdiff for a deb8u2. So you can decide what is the best way for the sec team and what version should be uploaded where. Best Regards, sandro -- Am Freitag, 14. Oktober 2016,

Bug#840546: CVE-2016-7966 kdepimlibs jessie

2016-10-14 Thread Salvatore Bonaccorso
Hi, Just an additional comment on the debdiff: On Fri, Oct 14, 2016 at 08:23:04PM +0200, Sandro Knauß wrote: > Hey, > > I now back ported the second part of the fix of the CVE. I updated the > version > deb8u1 from Scott. Should I create a deb8u2 for the additional patch? Please note, to

Bug#840546: CVE-2016-7966 kdepimlibs jessie

2016-10-14 Thread Moritz Muehlenhoff
On Fri, Oct 14, 2016 at 08:23:04PM +0200, Sandro Knauß wrote: > Hey, > > I now back ported the second part of the fix of the CVE. I updated the > version > deb8u1 from Scott. Should I create a deb8u2 for the additional patch? > > I attached the uptodate debdiff. Thanks, please upload.

Bug#840546: CVE-2016-7966 kdepimlibs jessie

2016-10-14 Thread Sandro Knauß
Hey, I now back ported the second part of the fix of the CVE. I updated the version deb8u1 from Scott. Should I create a deb8u2 for the additional patch? I attached the uptodate debdiff. Regards, sandro Am Donnerstag, 13. Oktober 2016, 18:19:35 CEST schrieb Moritz Mühlenhoff: > On Thu, Oct