Re: squeeze update of macopix?

2016-02-18 Thread Ying-Chun Liu (PaulLiu)
Ben Hutchings 於 2015年12月31日 06:37 寫道: > On Wed, 2015-12-30 at 20:19 +0800, Ying-Chun Liu (PaulLiu) wrote: > [...] >> I've made a patch. As attachment. > > I don't think it's a complete fix, as it doesn't check that there's > enough space for the terminating null (or shift sequence, where >

CVE-2015-7519

2016-02-18 Thread Thorsten Alteholz
Hi Linus, as others might be interested in the answer as well, I also send it to debian-lts@. On irc you wrote: 15:05 < Nirkus> have some old redmine running on squeeze-lts (yeah..) and since the update yesterday the following redmine code bails out with "private method `split' called for

Re: [PATCH] Given a package allow to check in which releases security support has ended

2016-02-18 Thread Holger Levsen
Hi Guido, On Mittwoch, 17. Februar 2016, Guido Günther wrote: > When triaging LTS issues I always have to look up what we still support > and what not. Attached script simplifies this a bit: > > $ bin/support-ended.py --lists /path/to/debian-security-support/ iceape > Package unsupported

Re: [PATCH] Given a package allow to check in which releases security support has ended

2016-02-18 Thread Guido Günther
On Thu, Feb 18, 2016 at 09:35:14AM -0500, Antoine Beaupré wrote: > On 2016-02-18 02:26:28, Guido Günther wrote: > > Hi, > > On Wed, Feb 17, 2016 at 01:39:41PM -0500, Antoine Beaupré wrote: > >> On 2016-02-17 12:13:35, Guido Günther wrote: > >> > When triaging LTS issues I always have to look up

Accepted libmatroska 0.8.1-1.1+deb6u1 (source amd64) into squeeze-lts

2016-02-18 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Thu, 18 Feb 2016 16:42:02 +0100 Source: libmatroska Binary: libmatroska0 libmatroska-dev Architecture: source amd64 Version: 0.8.1-1.1+deb6u1 Distribution: squeeze-lts Urgency: high Maintainer: Debian multimedia packages

[SECURITY] [DLA 420-1] libmatroska security update

2016-02-18 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libmatroska Version: 0.8.1-1.1+deb6u1 CVE ID : CVE-2014-9765 It was discovered that there was a invalid memory address issue in libmatroska, an extensible open standard audio/video container format. When reading a

Re: [PATCH] Given a package allow to check in which releases security support has ended

2016-02-18 Thread Antoine Beaupré
On 2016-02-18 02:26:28, Guido Günther wrote: > Hi, > On Wed, Feb 17, 2016 at 01:39:41PM -0500, Antoine Beaupré wrote: >> On 2016-02-17 12:13:35, Guido Günther wrote: >> > When triaging LTS issues I always have to look up what we still support >> > and what not. Attached script simplifies this a