Re: smb4k CVE-2017-8849

2017-08-12 Thread Moritz Mühlenhoff
On Wed, Jun 21, 2017 at 06:54:57PM +0200, Markus Koschany wrote: > Am 15.06.2017 um 18:49 schrieb Markus Koschany: > [...] > > Then I suggest we backport the Stretch version of smb4k to Wheezy and > > Jessie. I have done this a few minutes ago for Wheezy and it was quite > > painless. It pulls in a

Re: Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-12 Thread Chris Lamb
Hi Thorsten, > is the distribution in the changelog set correctly Yep. > How do I upload, i.e. to what queue do I dput, and do I use -sa? Can I link you to: https://wiki.debian.org/LTS/Development If there is something missing there let us know and we'll add it; thus saving the "next" perso

Re: Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-12 Thread Roberto C . Sánchez
Hi Thorsten, On Sat, Aug 12, 2017 at 05:26:22PM +, Thorsten Glaser wrote: > Hi LTS team, > > >>On Sat, Aug 12, 2017 at 12:36:57PM +0200, SC)bastien Delafond wrote: > > >>>For wheezy, you'll need to check directly with the Debian LTS team, that > >>>can be reached via debian-lts@lists.debian.

Re: Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-12 Thread Thorsten Glaser
Hi LTS team, >>On Sat, Aug 12, 2017 at 12:36:57PM +0200, SC)bastien Delafond wrote: >>>For wheezy, you'll need to check directly with the Debian LTS team, that >>>can be reached via debian-lts@lists.debian.org. is the attached debdiff ok to upload? (Specifically, is the distribution in the chang

Wheezy update of ruby-passenger?

2017-08-12 Thread Chris Lamb
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of ruby-passenger: https://security-tracker.debian.org/tracker/source-package/ruby-passenger Would you like to take care of this yourself? If yes, please follow the workfl