[SECURITY] [DLA 1767-1] monit security update

2019-04-26 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: monit Version: 1:5.9-1+deb8u2 CVE ID : CVE-2019-11454 CVE-2019-11455 Zack Flack found several issues in monit, a utility for monitoring and managing daemons or similar programs. CVE-2019-11454 An XSS

Accepted evolution 3.12.9~git20141130.241663-1+deb8u1 (source all amd64) into oldstable

2019-04-26 Thread Jonas Meurer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 18 Apr 2019 13:13:50 +0200 Source: evolution Binary: evolution libevolution evolution-common evolution-dev evolution-dbg evolution-plugins evolution-plugins-experimental Architecture: source all amd64 Version:

Re: RFT and RFC: Updates for evolution{,-data-server}

2019-04-26 Thread Jonas Meurer
Hi Mike, Mike Gabriel: > On  Mi 24 Apr 2019 12:56:18 CEST, Jonas Meurer wrote: > >> Jonas Meurer: >>> With evolution-data-server, the situation is slightly more complicated. >>> I'm still debugging issues with the patches[5] that are supposed to fix >>> the "[GPG] Mails that are not encrypted

Accepted monit 1:5.9-1+deb8u2 (source amd64) into oldstable

2019-04-26 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Fri, 26 Apr 2019 19:03:02 +0200 Source: monit Binary: monit Architecture: source amd64 Version: 1:5.9-1+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Sergey B Kirpichev Changed-By: Thorsten Alteholz Description:

[SECURITY] [DLA 1762-2] systemd regression update

2019-04-26 Thread Mike Gabriel
Package: systemd Version: 215-17+deb8u13 In the recently uploaded systemd security update (215-17+deb8u12 via DLA-1762-1), a regression was discovered in the fix for CVE-2017-18078. The observation of Debian jessie LTS users was, that after upgrading to +deb8u12 temporary files

Re: [SECURITY] [DLA 1762-1] systemd security update

2019-04-26 Thread Mike Gabriel
Hi, On Friday, 26 April 2019, Klimov, Evgeny wrote: > Hello Mike, and a good day to you. > > Our project uses Debian (Jessie so far) as the platform, and since > yesterday’s rebuilds with the updated systemd packages (systemd > 215-17+deb8u12), our working directories created via tmpfiles are