Re: pidgin

2016-06-28 Thread Salvatore Bonaccorso
Hi Brian, On Wed, Jun 29, 2016 at 08:35:26AM +1000, Brian May wrote: > Salvatore Bonaccorso writes: > > > Can you point me to the errors you found? Since I added I think most > > of those entries I would like to correct them if I wrongly commited. > > Sure. Hope I haven't made too many mistakes

Re: pidgin

2016-06-28 Thread Brian May
Salvatore Bonaccorso writes: > Can you point me to the errors you found? Since I added I think most > of those entries I would like to correct them if I wrongly commited. Sure. Hope I haven't made too many mistakes myself :-) * CVE-2016-2365 / TALOS-CAN-0133 https://bitbucket.org/pidgin/main/

Re: Security update of Gosa

2016-06-28 Thread Markus Koschany
On 21.06.2016 12:42, Mike Gabriel wrote: [...] > I'll get back to you tomorrow on this. Basically, I can do the upload my > self. > > Greets, > Mike Hi Mike, Is there any news? If you need assistance, don't hesitate to ask on debian-lts. Cheers, Markus signature.asc Description: OpenPGP dig

Re: Analysis of issue for phpmyadmin and request for comment on XSS issues

2016-06-28 Thread Markus Koschany
On 26.06.2016 23:47, Ola Lundqvist wrote: > Hi LTS team Hi! > > I have done some analysis of the issues for phpmyadmin. > > It would be good to know what your opinion about XSS issues for admin > software like phpmyadmin is. I do not see how that can be very > important. I mean you know the URL

Re: pidgin

2016-06-28 Thread Salvatore Bonaccorso
Hi Brian, On Tue, Jun 28, 2016 at 07:08:37AM +1000, Brian May wrote: > I found that a number of ther CVEs under security-tracker.debian.org > referenced the patch for the fix for the wrong CVE, so I had to retrieve > the correct patches from upstream git. Can you point me to the errors you found?

Re: [SECURITY] [DLA 532-1] movabletype-opensource security update

2016-06-28 Thread Raphael Hertzog
On Tue, 28 Jun 2016, Chris Lamb wrote: > > so that you stop doing the same mistake over and over. > > I think it might be unfair to characterise this as "over and over" when > it has occured twice AFAIK, especially when the file is not even in the > same repository.. Sorry, I did not want to poin

Re: Wheezy update of ruby-eventmachine?

2016-06-28 Thread Bálint Réczey
Hi Christian, 2016-06-28 7:27 GMT+02:00 Christian Hofstaedtler : > Hi, > > * Bálint Réczey [160628 00:28]: >> Dear Ruby and LTS Maintainers, >> >> I plan updating the ruby-eventmachine package in Wheezy LTS to >> fix the following security issue: >> https://security-tracker.debian.org/tracker/TEM

Re: pidgin

2016-06-28 Thread Brian May
Brian May writes: > Attached is a patch to fix all known security issues in pidgin in > Wheezy-LTS. > > I found that a number of ther CVEs under security-tracker.debian.org > referenced the patch for the fix for the wrong CVE, so I had to retrieve > the correct patches from upstream git. > > I al

Re: [SECURITY] [DLA 532-1] movabletype-opensource security update

2016-06-28 Thread Guido Günther
Hi, On Tue, Jun 28, 2016 at 08:55:32AM +0100, Chris Lamb wrote: > > so that you stop doing the same mistake over and over. > > I think it might be unfair to characterise this as "over and over" when it > has occured twice AFAIK, especially when the file is not even in the same > repository.. >

Re: [SECURITY] [DLA 532-1] movabletype-opensource security update

2016-06-28 Thread Guido Günther
On Tue, Jun 28, 2016 at 08:41:08AM +0200, Raphael Hertzog wrote: > On Mon, 27 Jun 2016, Chris Lamb wrote: > > Package: movabletype-opensource > > $ grep movabletype-opensource security-support-ended.deb7 > movabletype-opensource 5.1.4+dfsg-4+deb7u3 2016-02-06 Not supported in > Debi

Re: [SECURITY] [DLA 532-1] movabletype-opensource security update

2016-06-28 Thread Chris Lamb
> so that you stop doing the same mistake over and over. I think it might be unfair to characterise this as "over and over" when it has occured twice AFAIK, especially when the file is not even in the same repository.. > take some time to improve ~/bin/lts-cve-triage.py to show > unsupported pa