Bug#916435: stretch-pu: package cups/2.2.1-8+deb9u3

2019-02-05 Thread Adam D. Barratt
On 2019-02-05 10:05, Didier 'OdyX' Raboud wrote: Control: tags -1 +pending Le lundi, 4 février 2019, 23.06:44 h CET Adam D. Barratt a écrit : Please go ahead. Uploaded, thanks for the confirmation. For future reference, for p-u bugs we use "pending" for "has been accepted into p-u",

Bug#916435: stretch-pu: package cups/2.2.1-8+deb9u3

2019-02-05 Thread Didier 'OdyX' Raboud
Control: tags -1 +pending Le lundi, 4 février 2019, 23.06:44 h CET Adam D. Barratt a écrit : > Please go ahead. Uploaded, thanks for the confirmation. Cheers, OdyX

Bug#916435: stretch-pu: package cups/2.2.1-8+deb9u3

2019-02-04 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2018-12-14 at 14:09 +0100, Didier 'OdyX' Raboud wrote: > cups (2.2.1-8+deb9u3) stretch; urgency=low > >   * Backport upstream fixes for: > - CVE-2017-18248: DBUS notifications could crash the scheduler > - CVE-2018-4700: Linux session cookies used a

Bug#916435: stretch-pu: package cups/2.2.1-8+deb9u3

2018-12-14 Thread Didier 'OdyX' Raboud
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu CUPS in stable has two no-dsa security issues in stretch which I'd like to fix: - CVE-2017-18248: DBUS notifications could crash the scheduler - CVE-2018-4700: Linux session