Re: systemd CVE-2016-7796

2016-10-17 Thread Brian May
Brian May writes: > Will upload this afternoon or tomorrow unless any objections. Am getting suspicious that out of my two attempts to post an announcement for systemd, neither attempt got through. First attempt bounced from my MTA (bizare reason given), however 2nd should have got through. Bett

Wheezy update of icedove?

2016-10-17 Thread Chris Lamb
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of icedove: https://security-tracker.debian.org/tracker/source-package/icedove Would you like to take care of this yourself? If yes, please follow the workflow we ha

Wheezy update of potrace?

2016-10-17 Thread Chris Lamb
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of potrace: https://security-tracker.debian.org/tracker/source-package/potrace Would you like to take care of this yourself? If yes, please follow the workflow we ha

Re: Wheezy update of icedove?

2016-10-17 Thread Guido Günther
Hi, On Mon, Oct 17, 2016 at 02:07:31PM +0100, Chris Lamb wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of icedove: > https://security-tracker.debian.org/tracker/source-package/icedove > > Would you

Re: inline gpg signatures from mutt

2016-10-17 Thread Brian May
Salvatore Bonaccorso writes: > Btw, if you have a correctly configured local MTA, then maybe you can > just do the same as we do for DSA's: > > https://wiki.debian.org/DebianSecurity/AdvisoryCreation/SecFull#Sending_out_the_announcement_to_debian-security-announce > > write the DSA, sing the DSA

Re: inline gpg signatures from mutt

2016-10-17 Thread Salvatore Bonaccorso
Hi Brian, On Tue, Oct 18, 2016 at 08:02:53AM +1100, Brian May wrote: > Salvatore Bonaccorso writes: > > > Btw, if you have a correctly configured local MTA, then maybe you can > > just do the same as we do for DSA's: > > > > https://wiki.debian.org/DebianSecurity/AdvisoryCreation/SecFull#Sending

Re: inline gpg signatures from mutt

2016-10-17 Thread Brian May
Salvatore Bonaccorso writes: > If you have a fixed. Something like the following should work for DLA's > then: > > ( head -n 4 $1; tail -n +5 $1 | gpg --clearsign ) > $1.signed How about we look for the first empty line instead? Index: bin/sign-advisory.sh ==

Re: systemd CVE-2016-7796

2016-10-17 Thread Brian May
Brian May writes: > Am getting suspicious that out of my two attempts to post an > announcement for systemd, neither attempt got through. First attempt > bounced from my MTA (bizare reason given), however 2nd should have got > through. Better wait in case it was delayed somewhere, I will try > re