Re: squeeze update of tiff?

2016-01-04 Thread Mike Gabriel
Hi László, hi Ondřej, On Do 31 Dez 2015 19:01:33 CET, László Böszörményi (GCS) wrote: On Thu, Dec 31, 2015 at 10:04 AM, Ondřej Surý wrote: I have a git mirror[1] (git cvsimport) of upstream CVS and right now it's a tad bit confusing which patches are relevant to those

Re: squeeze update of tiff?

2015-12-31 Thread Ondřej Surý
Hi Ben and Laszlo, I have a git mirror[1] (git cvsimport) of upstream CVS and right now it's a tad bit confusing which patches are relevant to those CVEs. I will have more time cherry-picking the patches next week, so if somebody starts the work (even for unstable), I really won't mind. In fact

Re: squeeze update of tiff?

2015-12-31 Thread GCS
Hi Ondřej, Ben, On Thu, Dec 31, 2015 at 10:04 AM, Ondřej Surý wrote: > I have a git mirror[1] (git cvsimport) of upstream CVS and right now > it's a tad bit confusing which patches are relevant to those CVEs. I've packaged 4.0.6, fixed two CVEs and two other vulnerabilities

squeeze update of tiff?

2015-12-30 Thread Ben Hutchings
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of tiff: https://security-tracker.debian.org/tracker/CVE-2015-7554 https://security-tracker.debian.org/tracker/CVE-2015-8665

Re: squeeze update of tiff?

2015-12-30 Thread Ben Hutchings
On Wed, 2015-12-30 at 13:05 -0500, Jay Berkenbilt wrote: > Hello. I am no longer maintaining the tiff packages, but I have cc'ed > the new maintainers so that they can read the message quoted below and > respond if they are interested. I wonder whether it might make sense for > the debian-lts

squeeze update of tiff?

2015-12-29 Thread Ben Hutchings
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of tiff: https://security-tracker.debian.org/tracker/CVE-2015-7554 https://security-tracker.debian.org/tracker/CVE-2015-8665