Not the only one. Was: Re: Bug#757555: pam: CVE-2014-2583 pam_timestamp directory traversal issues

2014-08-10 Thread Lisandro Damián Nicanor Pérez Meyer
On Saturday 09 August 2014 18:46:09 Steve Langasek wrote: [snip] Which according to elsewhere in my mailbox, you've dealt with by uploading a 10-day delayed NMU. This is unacceptable. The NMU process always requires that you send your NMU diff to the BTS for review by the maintainer

Re: Not the only one. Was: Re: Bug#757555: pam: CVE-2014-2583 pam_timestamp directory traversal issues

2014-08-10 Thread Matthias Klose
Am 10.08.2014 um 15:25 schrieb Lisandro Damián Nicanor Pérez Meyer: Interesting, because yesterday I've got a patch [0] (cool, thanks a lot!) but stating that the package has been NMUed and uploaded to delayed/5. So, even 5 less days than in your case. Less than 5 minutes later, the

Re: Not the only one. Was: Re: Bug#757555: pam: CVE-2014-2583 pam_timestamp directory traversal issues

2014-08-10 Thread Manuel A. Fernandez Montecelo
Hi, 2014-08-10 14:25 Lisandro Damián Nicanor Pérez Meyer: On Saturday 09 August 2014 18:46:09 Steve Langasek wrote: [snip] Which according to elsewhere in my mailbox, you've dealt with by uploading a 10-day delayed NMU. This is unacceptable. The NMU process always requires that you send your

Re: Not the only one. Was: Re: Bug#757555: pam: CVE-2014-2583 pam_timestamp directory traversal issues

2014-08-10 Thread gregor herrmann
On Sun, 10 Aug 2014 15:52:51 +0200, Matthias Klose wrote: I wasn't aware that we are still supposed to do delayed/10 uploads, now that the default priority for uploads is medium. https://www.debian.org/doc/manuals/developers-reference/pkgs.html#nmu-guidelines recommends: * Upload fixing

Re: Not the only one. Was: Re: Bug#757555: pam: CVE-2014-2583 pam_timestamp directory traversal issues

2014-08-10 Thread Lisandro Damián Nicanor Pérez Meyer
On Sunday 10 August 2014 15:52:51 Matthias Klose wrote: Am 10.08.2014 um 15:25 schrieb Lisandro Damián Nicanor Pérez Meyer: Interesting, because yesterday I've got a patch [0] (cool, thanks a lot!) but stating that the package has been NMUed and uploaded to delayed/5. So, even 5 less days