LTS report for April 2019 - Abhijith PA (Slight correction)

2019-05-10 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 (Slight correction) April 2019 was my 15th month as a Debian LTS paid contributor. I was assigned 14 hours but I only able to do 4 hours. I will carry rest of the hours to next month. * mumble: I prepared 1.2.18[1] (version in stretch) for jessie

LTS report for April 2019 - Abhijith PA

2019-05-10 Thread Abhijith PA
March 2019 was my 14th month as a Debian LTS paid contributor. I was assigned 14 hours but I only able to do 4 hours. I will carry rest of the hours to next month. * mumble: I prepared 1.2.18[1] (version in stretch) for jessie. Tested with the PoC[2] and its still susceptible to attack, thus n

Backporting two dchpcd security patches to 6.0.5

2019-05-10 Thread Chris Lamb
[adding debian-lts@lists.debian.org to CC for visibility] Hi dhcpcd developers, I'm trying to backport two recent CVEs to the dhcpcd 6.0.5 (!) codebase as part of the Debian LTS [0] and I was just checking-in to get your response to a few thoughts of mine. The first is about CVE-2019-11579 regar

Bug in new libjs-jquery package from last week

2019-05-10 Thread Keith Erekson
I believe the update to libjs-jquery, released last week, contains a malformed jquery.min.js file. On a (legacy) system with multiple web apps that make use of /usr/share/javascript/jquery/jquery.min.js via symlink (specifically, icinga and pnp4nagios), web browsers throw a syntax error: jquery-1

LTS report for April 2019

2019-05-10 Thread Adrian Bunk
Hours worked: 8 hours Work done: DLA-1768-1 checkstyle CVE-2019-9658 Work on an update of libmatio is still ongoing. cu Adrian -- "Is there not promise of rain?" Ling Tan asked suddenly out of the darkness. There had been need of rain for many days. "Only a promise," Lao