(E)LTS report for May

2019-06-06 Thread Emilio Pozuelo Monfort
Hi, During the month of May, I spent 33h on LTS working on the following tasks: - openjdk-7 security update - qemu security update - security-tracker reviews - sqlite3 triage - sox: backported patches, run into stability bug in jessie not happening in sid, bisected it but fix was too invasive so

Re: RFC: remaining CVEs on libspring-java

2019-06-06 Thread Roberto C . Sánchez
On Thu, Jun 06, 2019 at 12:06:42AM -0400, Roberto C. Sánchez wrote: > On Tue, Jun 04, 2019 at 12:56:21PM +0200, Markus Koschany wrote: > > > The Spring framework is a very fine but > > also complex web framework. We use many parts of it as > > build-dependencies for other packages. I don't

[SECURITY] [DLA 1815-1] poppler security update

2019-06-06 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: poppler Version: 0.26.5-2+deb8u10 CVE ID : CVE-2019-10872 CVE-2019-12293 CVE-2019-12360 Several vulnerabilities have been found in the poppler PDF rendering library, which could result in denial of service or

Accepted poppler 0.26.5-2+deb8u10 (source amd64 all) into oldstable

2019-06-06 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Thu, 06 Jun 2019 12:02:44 +0200 Source: poppler Binary: libpoppler46 libpoppler-dev libpoppler-private-dev libpoppler-glib8 libpoppler-glib-dev libpoppler-glib-doc gir1.2-poppler-0.18 libpoppler-qt4-4 libpoppler-qt4-dev