Re: Wheezy update of libmad?

2018-05-11 Thread Kurt Roeckx
On Fri, May 11, 2018 at 09:25:17AM +0200, Emilio Pozuelo Monfort wrote: > Hi Kurt, > > On 30/01/18 21:59, Kurt Roeckx wrote: > > On Tue, Jan 30, 2018 at 08:33:53PM +0100, Ola Lundqvist wrote: > >> Dear maintainers, > >> > >> The Debian LTS team w

Re: Wheezy update of libmad?

2018-01-30 Thread Kurt Roeckx
On Tue, Jan 30, 2018 at 08:33:53PM +0100, Ola Lundqvist wrote: > Dear maintainers, > > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of libmad: > https://security-tracker.debian.org/tracker/CVE-2017-8372 >

Re: Security update of OpenSSL 1.0.1t-1+deb7u3

2017-11-08 Thread Kurt Roeckx
On Wed, Nov 08, 2017 at 11:22:24PM +0100, Markus Koschany wrote: > Am 08.11.2017 um 23:04 schrieb Kurt Roeckx: > > On Wed, Nov 08, 2017 at 10:07:57PM +0100, Markus Koschany wrote: > >> Hello Kurt, > >> > >> we saw that you reserved a DLA number for OpenSSL last

Re: Security update of OpenSSL 1.0.1t-1+deb7u3

2017-11-08 Thread Kurt Roeckx
On Wed, Nov 08, 2017 at 10:07:57PM +0100, Markus Koschany wrote: > Hello Kurt, > > we saw that you reserved a DLA number for OpenSSL last week but the new > version 1.0.1t-1+deb7u3 has not been uploaded yet. Is there anything we > can do to assist you? The package has been ready in svn since

Re: [pkg-mad-maintainers] Wheezy update of libmad?

2017-08-07 Thread Kurt Roeckx
On Mon, Aug 07, 2017 at 07:39:34AM -0400, Chris Lamb wrote: > Dear maintainer(s), > > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of libmad: > https://security-tracker.debian.org/tracker/source-package/libmad > > Would you like to

Re: should ca-certificates certdata.txt synchronize across all suites?

2017-07-22 Thread Kurt Roeckx
On Fri, Jul 21, 2017 at 04:47:23PM -0400, Antoine Beaupré wrote: > On 2017-07-21 22:19:20, Philipp Kern wrote: > > My point was that you state what your delta is and essentially boils > > down to attach the diff of what will actually happen to the .deb. I > > think it's generally fine to add new

Re: Wheezy update of ntp?

2017-03-22 Thread Kurt Roeckx
On Wed, Mar 22, 2017 at 09:02:16PM +0100, Ola Lundqvist wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of ntp: > https://security-tracker.debian.org/tracker/CVE-2017-6460 >

Re: openssl wheezy update

2017-01-31 Thread Kurt Roeckx
On Tue, Jan 31, 2017 at 11:13:55PM +0100, Emilio Pozuelo Monfort wrote: > Hi Kurt, > > I have prepared an update of openssl for wheezy based on 1.0.1t-1+deb8u6. I > have > done some smoke testing on it and it seems fine, but I haven't been able to > verify the three fixes as I can't find

Re: [pkg-ntp-maintainers] Wheezy update of ntp?

2016-11-21 Thread Kurt Roeckx
On Mon, Nov 21, 2016 at 11:13:13PM +0100, Ola Lundqvist wrote: > Hello dear maintainer(s), > > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of ntp: > https://security-tracker.debian.org/tracker/CVE-2016-7426 >

Re: Wheezy update of openssl?

2016-11-01 Thread Kurt Roeckx
On Tue, Nov 01, 2016 at 03:09:06PM +0100, Guido Günther wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of openssl: > https://security-tracker.debian.org/tracker/CVE-2016-8610 I will fix this soon.

[SECURITY] [DLA 637-1] openssl security update

2016-09-25 Thread Kurt Roeckx
Package: openssl Version: 1.0.1t-1+deb7u1 CVE ID : CVE-2016-2177 CVE-2016-2178 CVE-2016-2179 CVE-2016-2180 CVE-2016-2181 CVE-2016-2182 CVE-2016-6302 CVE-2016-6303 CVE-2016-6304 CVE-2016-6306 Several vulnerabilities were discovered in

Accepted openssl 1.0.1t-1+deb7u1 (source all amd64) into oldstable

2016-09-25 Thread Kurt Roeckx
: medium Maintainer: Debian OpenSSL Team <pkg-openssl-de...@lists.alioth.debian.org> Changed-By: Kurt Roeckx <k...@roeckx.be> Description: libcrypto1.0.0-udeb - crypto shared library - udeb (udeb) libssl-dev - SSL development libraries, header files and documentation libssl-doc - SSL

Re: OpenSSL for wheezy

2016-09-23 Thread Kurt Roeckx
On Fri, Sep 23, 2016 at 09:43:03PM +0200, Moritz Mühlenhoff wrote: > On Fri, Sep 23, 2016 at 09:38:10PM +0200, Kurt Roeckx wrote: > > So I would like to just upload the 1.0.1u version to > > wheezy-security. If nobody complains that is what I will do. > > Then the version n

OpenSSL for wheezy

2016-09-23 Thread Kurt Roeckx
Hi, The version in wheezy-security is currently 1.0.1e-2+deb7u21. Recently I've changed the jessie version from 1.0.1k to 1.0.1t without any problem. Supporting the 1.0.1e now requires a great deal of extra work because the patches just don't apply. If it's not because of the reformatting of

Re: Security update of ntp

2016-08-08 Thread Kurt Roeckx
On Mon, Aug 08, 2016 at 01:12:28PM +0200, Ola Lundqvist wrote: > Hi Kurt > > As a member of the LTS team I have started to look into a ntp security > update of CVE-2016-4953 mentioned here: > https://security-tracker.debian.org/tracker/source-package/ntp > > I see that you have prepared security

Re: wheezy update of ntp? (was: squeeze update of ntp?)

2016-06-01 Thread Kurt Roeckx
On Wed, Jun 01, 2016 at 07:23:22AM +0200, Santiago Ruano Rincón wrote: > > I have picked your patches (I hope all of them) from the svn to build a > test package, and have also taken a look to remaining issues. I have > only could "backport" the fix for CVE-2016-1551, the refclock >

Re: [pkg-ntp-maintainers] squeeze update of ntp?

2016-05-18 Thread Kurt Roeckx
On Wed, May 18, 2016 at 01:24:37PM -0400, Antoine Beaupré wrote: > On 2016-02-13 05:49:24, Kurt Roeckx wrote: > > On Sat, Feb 13, 2016 at 10:06:23AM +, Damyan Ivanov wrote: > >> Hello dear maintainer(s), > >> > >> The Debian LTS team would l

[SECURITY] [DLA 456-1] openssl security update

2016-05-03 Thread Kurt Roeckx
Package: openssl Version: 1.0.1e-2+deb7u21 CVE ID : CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 CVE-2016-2109 CVE-2016-2176 Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-2105 Guido Vranken

Re: tracking security issues without CVEs

2016-03-12 Thread Kurt Roeckx
On Sun, Mar 06, 2016 at 03:33:16PM +1100, Brian May wrote: > Hello, > > Just wondering if there is some other way we can track security issues > for when CVEs are not available. > > Thinking of imagemagick here, it has a lot of security issues, and > requests for CVEs are not getting any

[SECURITY] [DLA 421-1] openssl security update

2016-02-20 Thread Kurt Roeckx
will end soon. If you are using openssl you should upgrade to wheezy or preferably jessie. The version in those versions contain many security improvements. Kurt Roeckx signature.asc Description: PGP signature

Accepted openssl 0.9.8o-4squeeze23 (source amd64) into squeeze-lts

2016-02-20 Thread Kurt Roeckx
: Debian OpenSSL Team <pkg-openssl-de...@lists.alioth.debian.org> Changed-By: Kurt Roeckx <k...@roeckx.be> Description: libcrypto0.9.8-udeb - crypto shared library - udeb (udeb) libssl-dev - SSL development libraries, header files and documentation libssl0.9.8 - SSL shared libraries

Re: [pkg-ntp-maintainers] squeeze update of ntp?

2016-02-13 Thread Kurt Roeckx
On Sat, Feb 13, 2016 at 10:06:23AM +, Damyan Ivanov wrote: > Hello dear maintainer(s), > > The Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of ntp: > https://security-tracker.debian.org/tracker/source-package/ntp I was under the

Re: [pkg-ntp-maintainers] squeeze update of ntp?

2016-02-13 Thread Kurt Roeckx
On Sat, Feb 13, 2016 at 03:55:31PM +, Damyan Ivanov wrote: > -=| Kurt Roeckx, 13.02.2016 11:49:24 +0100 |=- > > On Sat, Feb 13, 2016 at 10:06:23AM +, Damyan Ivanov wrote: > > > Hello dear maintainer(s), > > > > > > The Debian LTS team would l

[SECURITY] [DLA 358-1] openssl security update

2015-12-03 Thread Kurt Roeckx
Package: openssl Version: 0.9.8o-4squeeze22 CVE ID : CVE-2015-3195 When presented with a malformed X509_ATTRIBUTE structure OpenSSL will leak memory. This structure is used by the PKCS#7 and CMS routines so any application which reads PKCS#7 or CMS data from untrusted

Re: ntp security update

2015-10-28 Thread Kurt Roeckx
On Wed, Oct 28, 2015 at 09:35:59AM +0900, Ben Hutchings wrote: > On Tue, 2015-10-27 at 21:57 +0100, Kurt Roeckx wrote: > > On Sun, Oct 25, 2015 at 01:30:18PM +0900, Ben Hutchings wrote: > > > I've looked through the upstream repository for the patches that fix he > > >

Accepted ntp 1:4.2.6.p2+dfsg-1+deb6u4 (source all amd64) into squeeze-lts

2015-10-28 Thread Kurt Roeckx
ain...@lists.alioth.debian.org> Changed-By: Kurt Roeckx <k...@roeckx.be> Description: ntp- Network Time Protocol daemon and utility programs ntp-doc- Network Time Protocol documentation ntpdate- client for setting system time from NTP servers Changes: ntp (1:4.2.6.p2+d

[SECURITY] [DLA 335-1] ntp security update

2015-10-28 Thread Kurt Roeckx
Package: ntp Version: 1:4.2.6.p2+dfsg-1+deb6u4 CVE ID : CVE-2015-5146 CVE-2015-5194 CVE-2015-5195 CVE-2015-5219 CVE-2015-5300 CVE-2015-7691 CVE-2015-7692 CVE-2015-7701 CVE-2015-7702 CVE-2015-7703 CVE-2015-7704 CVE-2015-7850

Re: ntp security update

2015-10-27 Thread Kurt Roeckx
On Sun, Oct 25, 2015 at 01:30:18PM +0900, Ben Hutchings wrote: > I've looked through the upstream repository for the patches that fix he > recently announced issues.  Quite a few of them turned out not to apply > to squeeze, or the newer stable releases, and I've updated the security > tracker

Re: ntp security update

2015-10-25 Thread Kurt Roeckx
On Sun, Oct 25, 2015 at 11:19:03AM +0100, Kurt Roeckx wrote: > On Sun, Oct 25, 2015 at 01:30:18PM +0900, Ben Hutchings wrote: > > I've looked through the upstream repository for the patches that fix he > > recently announced issues.  Quite a few of them turned out not to apply

Re: ntp security update

2015-10-25 Thread Kurt Roeckx
On Mon, Oct 26, 2015 at 06:55:06AM +0900, Ben Hutchings wrote: > On Sun, 2015-10-25 at 22:45 +0100, Kurt Roeckx wrote: > > On Mon, Oct 26, 2015 at 06:13:07AM +0900, Ben Hutchings wrote: > [...] > > > > While I have addiotional patches for: > > > > CVE-2014-9750

Re: ntp security update

2015-10-25 Thread Kurt Roeckx
On Mon, Oct 26, 2015 at 06:13:07AM +0900, Ben Hutchings wrote: > On Sun, 2015-10-25 at 11:19 +0100, Kurt Roeckx wrote: > > On Sun, Oct 25, 2015 at 01:30:18PM +0900, Ben Hutchings wrote: > > > I've looked through the upstream repository for the patches that fix he > > >

[SECURITY] [DLA 247-1] openssl security update

2015-06-17 Thread Kurt Roeckx
Package: openssl Version: 0.9.8o-4squeeze21 CVE ID : CVE-2014-8176 CVE-2015-1789 CVE-2015-1790 CVE-2015-1791 CVE-2015-1792 CVE-2015-4000 Multiple vulnerabilities were discovered in OpenSSL, a Secure Sockets Layer toolkit. CVE-2014-8176 Praveen

Re: squeeze update of ntp?

2015-04-10 Thread Kurt Roeckx
On Fri, Apr 10, 2015 at 11:05:47PM +0200, Raphael Hertzog wrote: Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of ntp: https://security-tracker.debian.org/tracker/CVE-2015-1798

Re: squeeze update of ntp?

2015-04-10 Thread Kurt Roeckx
On Fri, Apr 10, 2015 at 11:33:22PM +0200, Raphael Hertzog wrote: Hi, On Fri, 10 Apr 2015, Kurt Roeckx wrote: On Fri, Apr 10, 2015 at 11:05:47PM +0200, Raphael Hertzog wrote: Would you like to take care of this yourself? We are still understaffed so any help is always highly appreciated

Re: squeeze update of openssl?

2015-03-09 Thread Kurt Roeckx
On Mon, Mar 09, 2015 at 04:29:43PM +0100, Raphael Hertzog wrote: Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of openssl: https://security-tracker.debian.org/tracker/CVE-2015-0209