Re: qemu: CVE-2016-7116

2016-09-04 Thread Guido Günther
On Sun, Sep 04, 2016 at 08:06:11PM +0200, Thorsten Alteholz wrote: > Hi Guido, > > On Sun, 4 Sep 2016, Guido Günther wrote: > > no-dsa should be used very scarcely in LTS since we don't have a s-p-u > > to fix minor issues and reading the RedHat entry[1]: > > yes, but ... > > > "A privileged use

Re: matrixssl

2016-09-04 Thread Christopher Samuel
On 02/09/16 18:42, Brian May wrote: > sslio[8259]: fatal: unable to read cert or key file: no error I found that error reported in an unrelated bug report, the solution seems to be: https://bugs.contribs.org/show_bug.cgi?id=7664#c4 > I have been hit by the problem lamented by Jean Franco whiel

Re: qemu: CVE-2016-7116

2016-09-04 Thread Thorsten Alteholz
Hi Guido, On Sun, 4 Sep 2016, Guido Günther wrote: no-dsa should be used very scarcely in LTS since we don't have a s-p-u to fix minor issues and reading the RedHat entry[1]: yes, but ... "A privileged user inside guest could use this flaw to access undue files on the host." ... you should

Re: qemu: CVE-2016-7116

2016-09-04 Thread Guido Günther
Hi Thorsten, On Sun, Sep 04, 2016 at 05:23:40PM +0200, Thorsten Alteholz wrote: > Hi Hugo, > > are you aware that this CVE is marked as in Jessie and soon will be > in Wheezy as well. > > So unless you disagree with this , it would be better to avoid any > potential regression and not upload qem

LTS report for August 2016

2016-09-04 Thread Emilio Pozuelo Monfort
Hi, This month I was allocated 14.75 hours to work on Debian-LTS. I spent 13.5 hours doing the following: - openjdk-7: after some back and forth, finally pushed the update for openjdk-7 - icedtea-web: pushed the update to make icedtea-plugin default to openjdk-7 - fontconfig: prepared, tested and

Re: Wheezy update of libtomcrypt?

2016-09-04 Thread Michael Stapelberg
Thanks for your work on LTS. Time does not permit me to do any of this work myself. Please go ahead and make any changes as you see fit, there’s no need for my review. On Sun, Sep 4, 2016 at 5:38 PM, Thorsten Alteholz wrote: > Hello Michael, > > the Debian LTS team would like to fix the securi

Wheezy update of libtomcrypt?

2016-09-04 Thread Thorsten Alteholz
Hello Michael, the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of libtomcrypt: https://security-tracker.debian.org/tracker/CVE-2016-6129 Would you like to take care of this yourself? If yes, please follow the workflow we have defined here

Wheezy update of jsch?

2016-09-04 Thread Thorsten Alteholz
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of jsch: https://security-tracker.debian.org/tracker/source-package/jsch Would you like to take care of this yourself? If yes, please follow the workflow we have de

Re: qemu: CVE-2016-7116

2016-09-04 Thread Salvatore Bonaccorso
Hi Hugo, On Sun, Sep 04, 2016 at 01:25:56PM +0200, Hugo Lefeuvre wrote: > > Yes, qemu is supported (and there has was lots of file renaming after > > the Wheezy version). If you handle qemu please look at qemu-kvm as well > > (they're the same version). > > Thanks for the hint. > > By the way, c

Re: qemu: CVE-2016-7116

2016-09-04 Thread Thorsten Alteholz
Hi Hugo, are you aware that this CVE is marked as in Jessie and soon will be in Wheezy as well. So unless you disagree with this , it would be better to avoid any potential regression and not upload qemu or qemu-kvm. Thorsten

Re: qemu: CVE-2016-7116

2016-09-04 Thread Hugo Lefeuvre
> Yes, qemu is supported (and there has was lots of file renaming after > the Wheezy version). If you handle qemu please look at qemu-kvm as well > (they're the same version). Thanks for the hint. By the way, could you explain me why this CVE is still labeled RESERVED, although a public fix expla