munin regression update possibly needed

2017-03-01 Thread Salvatore Bonaccorso
Hi LTS team, Please CC me on replies. You might want to double check if munin for wheezy needs as well a regression update for the zooming problem, #856455. But please be aware that the DSA-3794-2 update which I issued introduces another regression, #856536 which should not be introduced as well

Re: Guessing package version for DLA template

2017-03-01 Thread Salvatore Bonaccorso
Hi Balint, Seb, On Thu, Mar 02, 2017 at 06:53:14AM +, Sébastien Delafond wrote: > On 2017-03-02, Bálint Réczey wrote: > > I have prepared a patch to optionally prepare the template using: > > bin/gen-DSA package.changes > > That looks OK, just merge it and we can adapt it later on if needed

Re: Guessing package version for DLA template

2017-03-01 Thread Sébastien Delafond
On 2017-03-02, Bálint Réczey wrote: > I have prepared a patch to optionally prepare the template using: > bin/gen-DSA package.changes That looks OK, just merge it and we can adapt it later on if needed (for instance it would need to handle multiple changes files, for when both stable and oldstabl

mcollective cve-2016-2788

2017-03-01 Thread Brian May
Details of this bug seem to be very scarce. I can't find any information on how to reproduce, and I can't find git source. I can't even tell if wheezy is vulnerable or not. Furthermore this package is very old in all distributions including unstable. About the best I can find is this bug is prese

Re: Guessing package version for DLA template

2017-03-01 Thread Bálint Réczey
Hi, Thanks for all the input! 2017-02-28 9:12 GMT+01:00 Sébastien Delafond : > On Feb/28, Peter Palfrader wrote: >> Maybe we should be able to pass the name of the .changes file to >> gen-DSA, and then the script can go and use all the information from >> there? > > Implementation-wise, this soun

Re: [SECURITY] [DSA 3792-1] libreoffice security update

2017-03-01 Thread Bálint Réczey
Hi, 2017-03-01 21:48 GMT+01:00 Rene Engelhard : > Hi, > > On Tue, Feb 28, 2017 at 01:51:08AM +0100, Bálint Réczey wrote: >> Do you have a PoC for testing? >> I tried triggering the issue on Wheezy without any luck so far. > > Forwarded you the original mail from September in private mail. Thanks!

Re: [SECURITY] [DSA 3792-1] libreoffice security update

2017-03-01 Thread Rene Engelhard
Hi, On Tue, Feb 28, 2017 at 01:51:08AM +0100, Bálint Réczey wrote: > Do you have a PoC for testing? > I tried triggering the issue on Wheezy without any luck so far. Forwarded you the original mail from September in private mail. Regards, Rene

LTS report February 2017

2017-03-01 Thread Antoine Beaupré
For February, I spent about 3 hours as follows: * review and upload apache2 DLA-841-1 fixing the nasty and obscure CVE-2016-8743, thanks everyone for the reviews and testing! * examine and postpone the kgb-bot DOS issue * backport the CVE-2016-7478 patch for php5 I'll catchup with my hours in m

LTS Report for February 2017

2017-03-01 Thread Roberto C . Sánchez
For February I spent 5.5 hours as follows: - php5: CVE-2016-10159, CVE-2016-10160, CVE-2016-10161, PHP bug 71323, PHP bug 70979, PHP bug 71039, PHP bug 71459, PHP bug 71391, and PHP bug 71335: integrated/backported upstream fixes, verified fixes, and ensured unit tests passed - php5: built a

Re: Should icedove be renamed in oldstable?

2017-03-01 Thread Ola Lundqvist
Hi Guido Now I understand the point. No objections then. // Ola On 28 February 2017 at 23:15, Guido Günther wrote: > On Tue, Feb 28, 2017 at 09:17:38PM +0100, Ola Lundqvist wrote: > > Hi LTS Team, Guido and Christoph > > > > In the dla-needed.txt file I found the following lines: > > > > "iced

Re: Should icedove be renamed in oldstable?

2017-03-01 Thread Korte
On Tue, 28 Feb 2017 23:15:24 +0100 Guido Günther wrote: > On Tue, Feb 28, 2017 at 09:17:38PM +0100, Ola Lundqvist wrote: > > Hi LTS Team, Guido and Christoph > > > > In the dla-needed.txt file I found the following lines: > > > > "icedove > > NOTE: maintainer currenlty planx to rename to thun