LTS report for December 2018

2019-01-03 Thread Lucas Kanashiro
Hi, In December I was allocated 4h and I spent only 3h of them (I'll catch up the remaining 1h during January 2019) doing the following: * ghostscript: Fixed CVE-2018-19134 and CVE-2018-19478. The DLA was properly sent [1]. * phpmyadmin: Trying to reproduce CVE-2018-19968. [1]

Re: MySQL 5.5 EOL before Debian 8 LTS ends

2019-01-03 Thread Jan Ingvoldstad
On 2019-01-03 10:40, Otto Kekäläinen wrote: You can always cross-migrate via logical database dumps as .sql files instead of in-place binary files. This is not guaranteed to work, and you need to take special care with mysqldump and mysql options for such migration dumps. For instance, if

Re: MySQL 5.5 EOL before Debian 8 LTS ends

2019-01-03 Thread Emilio Pozuelo Monfort
On 03/01/2019 10:40, Otto Kekäläinen wrote: > Hello! > > to 3. tammik. 2019 klo 3.40 Robie Basak (robie.ba...@canonical.com) kirjoitti: >> >> Hi Otto and the LTS team, >> >> On Mon, Dec 31, 2018 at 10:50:34AM +0200, Otto Kekäläinen wrote: >>> I think that is *if* makes sense to engineer some

Re: MySQL 5.5 EOL before Debian 8 LTS ends

2019-01-03 Thread Otto Kekäläinen
Hello! to 3. tammik. 2019 klo 3.40 Robie Basak (robie.ba...@canonical.com) kirjoitti: > > Hi Otto and the LTS team, > > On Mon, Dec 31, 2018 at 10:50:34AM +0200, Otto Kekäläinen wrote: > > I think that is *if* makes sense to engineer some automatic upgrade path in > > an LTS release, then it

[SECURITY] [DLA 1627-1] qtbase-opensource-src security update

2019-01-03 Thread Adrian Bunk
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: qtbase-opensource-src Version: 5.3.2+dfsg-4+deb8u3 CVE ID : CVE-2018-15518 CVE-2018-19870 CVE-2018-19873 Multiple issues were fixed in Qt. CVE-2018-15518 A double-free or corruption during parsing of a specially