Re: [SECURITY] [DSA 4371-1] apt security update

2019-01-27 Thread Steve McIntyre
On Sun, Jan 27, 2019 at 06:33:29PM +, Steve McIntyre wrote: >On Thu, Jan 24, 2019 at 12:39:29PM +0100, Emilio Pozuelo Monfort wrote: >> >>Just to clarify: there is no separate -lts suite anymore, so it'd >>just need to pull from security (which still needs changes as you >>mentioned). >> >>Can

Re: [SECURITY] [DSA 4371-1] apt security update

2019-01-27 Thread Steve McIntyre
On Thu, Jan 24, 2019 at 12:39:29PM +0100, Emilio Pozuelo Monfort wrote: >Hi Steve, > >On 22/01/2019 14:50, Steve McIntyre wrote: >> On Tue, Jan 22, 2019 at 01:44:12PM +, Ben Hutchings wrote: >>> However, APT is used during initial installation and we don't have any >>> provision for updating in

Re: qemu - CVE-2018-19665: bt subsystem mishandles negative length variables

2019-01-27 Thread Adrian Zaugg
On 1/12/19 5:52 PM, Hugo Lefeuvre wrote: the subsystem doesn't seem to be very actively maintained and that the user base is quite small, it is maybe better to mark this no-dsa in stretch and Please don't forget thet Debian has derivates that do not get summed up in popcon.d.o. So the user