Re: Security update of nettle

2016-08-06 Thread Andreas Metzler
On 2016-08-07 Ola Lundqvist wrote: > On Sat, Aug 6, 2016 at 8:40 PM, Niels Möller wrote: >> Ola Lundqvist writes: >>> Magnus, Niels and I have been discussing the nettle update due to >>> https://security-tracker.debian.org/tracker/CVE-2016-6489 >> Please note that some coordinatoino with gnutl

Re: Icedtea plugin

2016-08-06 Thread Emilio Pozuelo Monfort
On 06/08/16 10:38, Markus Koschany wrote: > On 06.08.2016 10:18, Guido Günther wrote: >> Hi, >> On Fri, Aug 05, 2016 at 11:49:33PM +0200, Emilio Pozuelo Monfort wrote: >>> On 02/08/16 19:48, Emilio Pozuelo Monfort wrote: On 01/08/16 23:26, Markus Koschany wrote: > On 01.08.2016 23:01, Emil

Re: Security update of nettle

2016-08-06 Thread Ola Lundqvist
Hi Niels and gnutls maintainers I do not think coordination with gnutls is needed. I can not see that gnutls depend on nettle in wheezy. I can see that it can potentially do that, but I do not think it do. There are no dependencies declared on nettle library and from unstable changelog it looks l

Re: Security update of nettle

2016-08-06 Thread Niels Möller
Ola Lundqvist writes: > Magnus, Niels and I have been discussing the nettle update due to > https://security-tracker.debian.org/tracker/CVE-2016-6489 Please note that some coordinatoino with gnutls may be needed, to avoid a denial-of-service problem involving invalid private keys. > I suggest s

Wheezy update of mupdf?

2016-08-06 Thread Jonas Meurer
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of mupdf: https://security-tracker.debian.org/tracker/CVE-2016-6525 Would you like to take care of this yourself? If yes, please follow the workflow we have defined

Re: Wheezy update of libreoffice #2 (CVE-2016-1513)

2016-08-06 Thread Balint Reczey
Hi Rene, On 08/06/2016 09:07 AM, Rene Engelhard wrote: > Hi, > > On Fri, Aug 05, 2016 at 07:00:11PM +0200, Bálint Réczey wrote: >> 2016-08-04 19:34 GMT+02:00 Rene Engelhard : >>> Hi, >>> >>> On Thu, Aug 04, 2016 at 09:12:04AM +0200, Rene Engelhard wrote: I noticed Balint did some additional

Re: Icedtea plugin

2016-08-06 Thread Markus Koschany
On 06.08.2016 10:18, Guido Günther wrote: > Hi, > On Fri, Aug 05, 2016 at 11:49:33PM +0200, Emilio Pozuelo Monfort wrote: >> On 02/08/16 19:48, Emilio Pozuelo Monfort wrote: >>> On 01/08/16 23:26, Markus Koschany wrote: On 01.08.2016 23:01, Emilio Pozuelo Monfort wrote: > On 31/07/16 19:41

Re: Icedtea plugin

2016-08-06 Thread Guido Günther
Hi, On Fri, Aug 05, 2016 at 11:49:33PM +0200, Emilio Pozuelo Monfort wrote: > On 02/08/16 19:48, Emilio Pozuelo Monfort wrote: > > On 01/08/16 23:26, Markus Koschany wrote: > >> On 01.08.2016 23:01, Emilio Pozuelo Monfort wrote: > >>> On 31/07/16 19:41, Roberto C. Sánchez wrote: > On Sun, Jul

Re: Wheezy update of libreoffice #2 (CVE-2016-1513)

2016-08-06 Thread Rene Engelhard
Hi, On Fri, Aug 05, 2016 at 07:00:11PM +0200, Bálint Réczey wrote: > 2016-08-04 19:34 GMT+02:00 Rene Engelhard : > > Hi, > > > > On Thu, Aug 04, 2016 at 09:12:04AM +0200, Rene Engelhard wrote: > >> I noticed Balint did some additional changes to deb7u7 (build-depends > >> on fixed graphite2 - than