Re: [SECURITY] [DLA 737-1] roundcube security update

2016-12-09 Thread Alexander Wirt
On Fri, 09 Dec 2016, Markus Koschany wrote: > On 09.12.2016 11:23, Chris Lamb wrote: > > Hi Christoph, > > > >> will there also be a fixed wheezy-backports version? It is at 0.9.5. > > > > As this CVE/DLA is still fresh in my mind, I've gone ahead and uploaded a > > 0.9.5-1~bpo70+1.1 to

Re: [SECURITY] [DLA 737-1] roundcube security update

2016-12-09 Thread Markus Koschany
On 09.12.2016 11:23, Chris Lamb wrote: > Hi Christoph, > >> will there also be a fixed wheezy-backports version? It is at 0.9.5. > > As this CVE/DLA is still fresh in my mind, I've gone ahead and uploaded a > 0.9.5-1~bpo70+1.1 to wheezy-backports. > > Enjoy :) > Hi, I cannot really recommend

Re: Wheezy update of unzip?

2016-12-09 Thread Santiago Vila
On Thu, 8 Dec 2016, Chris Lamb wrote: > If that workflow is a burden to you, feel free to just prepare an > updated source package and send it to debian-lts@lists.debian.org > (via a debdiff, or with an URL pointing to the source package, > or even with a pointer to your packaging repository),

Re: Wheezy update of unzip?

2016-12-09 Thread Chris Lamb
Santiago Vila wrote: > I'd like to fix this in unstable first, then I guess it would be a > little easier for you to make the update for wheezy. Is that ok? Perfect. Many thanks. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

Re: [SECURITY] [DLA 737-1] roundcube security update

2016-12-09 Thread Christoph Martin
Hi Chris, Am 09.12.2016 um 11:23 schrieb Chris Lamb: > Hi Christoph, > >> will there also be a fixed wheezy-backports version? It is at 0.9.5. > > As this CVE/DLA is still fresh in my mind, I've gone ahead and uploaded a > 0.9.5-1~bpo70+1.1 to wheezy-backports. > Thanks a lot. Christoph --

Re: [SECURITY] [DLA 737-1] roundcube security update

2016-12-09 Thread Christoph Martin
Hi, will there also be a fixed wheezy-backports version? It is at 0.9.5. Regards Christoph Am 08.12.2016 um 20:01 schrieb Chris Lamb: > Package: roundcube > Version: 0.7.2-9+deb7u5 > Debian Bug : 847287 > > It was discovered that there was a vulnerability where a remote