Introduction

2019-10-01 Thread Utkarsh Gupta
Hey, I joined back in July as a trainee and now a part of the LTS team since this October, and all this while I forgot to introduce myself, so here it goes.. I am 19 y/o Debian Maintainer (opening a NM process for DM -> DD this weekend :)). Being a part of the Ruby, JS, Golang, Perl, and the

Re: Training process

2019-10-01 Thread Utkarsh Gupta
Hey, On Mon, Sep 30, 2019 at 01:13:45PM +0200, Sylvain Beucler wrote: > Hi, > > First, welcome to Utkarsh Gupta in the team :) Thank you! :D > >From what I understand there was a training during July and August, > resulting in active status this month. > I saw zero traces of this training

Accepted firefox-esr 60.9.0esr-1~deb8u2 (source i386 all) into oldoldstable

2019-10-01 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Tue, 01 Oct 2019 10:05:19 +0200 Source: firefox-esr Binary: firefox-esr iceweasel firefox-esr-dbg iceweasel-dbg firefox-esr-l10n-all iceweasel-l10n-all firefox-esr-l10n-ach iceweasel-l10n-ach firefox-esr-l10n-af iceweasel-l10n-af

Re: firefox-esr 60.9.0esr-1~deb8u1 i386 build

2019-10-01 Thread Emilio Pozuelo Monfort
On 30/09/2019 06:40, Sylvain Beucler wrote: > Hello, > > On 27/09/2019 23:12, Pascal Hambourg wrote: >> Sorry to insist again, but is there any hope that the i386 build will >> be available ? > > It seems this is a memory issue on the builder: > > virtual memory exhausted: Operation not

Re: Training process

2019-10-01 Thread Sylvain Beucler
Hi, Team ACME gets a new member. No reaction. When asked what happened: - team member A: no time - team member B: not a documented process - team member C: maybe new member did something wrong - team member D: will be introduced in 3 weeks with the report - team member E: I thought it was a user

[SECURITY] [DLA 1940-1] linux-4.9 security update

2019-10-01 Thread Ben Hutchings
Package: linux-4.9 Version: 4.9.189-3+deb9u1~deb8u1 CVE ID : CVE-2019-14821 CVE-2019-14835 CVE-2019-15117 CVE-2019-15118 CVE-2019-15902 Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of

Re: [SECURITY] [DLA 1942-1] phpbb3 security update

2019-10-01 Thread Sylvain Beucler
Hi Gabriel, I see you reverted affectation for CVE-2019-13376. CVE-2019-13376 is an follow-up fix to CVE-2019-16993 (2016) which I registered just yesterday toclarify that we've been missing this earlier fix (AFAICS unsuccessfully ;)). CVE-2019-13376 applies to 3.2.7 which already has the fix

LTS/ELTS Report for September 2019

2019-10-01 Thread Roberto C . Sánchez
For September I spent 16 hours on the following LTS tasks: - ansible: multiple issues, including the recently reported CVE-2019-10156 and several previously no-dsa/postponed fixes - mongodb: CVE-2019-2386, triaged and found to not apply - libcommons-compress-java: CVE-2019-12402 - php5: fix for

Re: Training process

2019-10-01 Thread Raphael Hertzog
Hi, On Mon, 30 Sep 2019, Sylvain Beucler wrote: > From what I understand there was a training during July and August, > resulting in active status this month. > I saw zero traces of this training besides a passing anonymous > mention in Raphael's reports. > Possibly we can clarify this a lil'