Re: CVE-2016-8685 in potrace

2017-04-01 Thread Ola Lundqvist
Hi Hugo I do not have any objection on marking it as no-dsa, especially since it is that already for jessie. However I thought I should have a check but I can not find a patch. The patch mentioned here, gives a 404. https://blogs.gentoo.org/ago/2016/08/29/potrace-invalid-memory-access-in-findnext

Re: improving the report-vuln script

2017-04-01 Thread Antoine Beaupré
On 2017-03-31 21:32:27, Salvatore Bonaccorso wrote: > Hi Antoine, > > I just have pushed your changes (and only the minor changes, but not > all). Excellent, thanks. [...] > JFTR. If you use reportbug this *is* actually the behaviour, so > actually no policy-change in that sense. Whoever uses re

Re: Bug#858973: wheezy-pu: package ejabberd/2.1.10-4+deb7u2

2017-04-01 Thread Guido Günther
Hi Philipp, On Sat, Apr 01, 2017 at 11:52:28AM +0200, Philipp Huebner wrote: > Hi, > > Am 31.03.2017 um 14:32 schrieb Guido Günther: > > > I've tested the package (ejabberdctl, connecting different clients) and > > it looks good. During the upgrade I get this list of errors though: > > > > d

Re: Review and help test Wheezy LTS update of Samba

2017-04-01 Thread Mathieu Parent
2017-04-01 4:12 GMT+02:00 Roberto C. Sánchez : > All, Hello Roberto, > I have prepared the 3.6.6-6+deb7u12 update of Samba for Wheezy LTS. The > update incorporates some cherry-picked commits from upstream, the fix > for CVE-2017-2619, and a fix for a regression introduced by upstream's > fix for

LTS Report for March 2017

2017-04-01 Thread Roberto C . Sánchez
For March I had 22.5 hours available (some carried over from February) and I spent 21.5 hours as follows: - imagemagick: CVE-2016-10062, CVE-2017-6498, CVE-2017-6500: integrated and/or backported fixes, built and tested packages, uploaded, and published DLA - samba: CVE-2017-2619: identified

Re: Bug#858973: wheezy-pu: package ejabberd/2.1.10-4+deb7u2

2017-04-01 Thread Philipp Huebner
Hi, Am 31.03.2017 um 14:32 schrieb Guido Günther: > I've tested the package (ejabberdctl, connecting different clients) and > it looks good. During the upgrade I get this list of errors though: > > dpkg -i ejabberd_2.1.10-4+deb7u2_amd64.deb > (Reading database ... 29454 files and direct