[DLA 1835-1] python3.4 security update breaks upgrade (SyntaxError: invalid syntax)

2019-06-25 Thread Bas Couwenberg
The python3.4 upgrade failed: Setting up python3.4 (3.4.2-1+deb8u3) ... File "/usr/lib/python3.4/http/client.py", line 1014 raise InvalidURL(f"URL can't contain control characters. {url!r} " ^ SyntaxError: invalid

[SECURITY] [DLA 1297-1] freexl security update

2018-03-01 Thread Bas Couwenberg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: freexl Version: 1.0.0b-1+deb7u5 CVE ID : CVE-2018-7435 CVE-2018-7436 CVE-2018-7437 CVE-2018-7438 CVE-2018-7439 Leon reported five heap-based buffer-overflow vulnerabilities in FreeXL.

Accepted freexl 1.0.0b-1+deb7u4 (source amd64) into oldoldstable

2017-09-17 Thread Bas Couwenberg
;da...@debian.org> Changed-By: Bas Couwenberg <sebas...@debian.org> Description: libfreexl-dev - library for direct reading of Microsoft Excel spreadsheets - deve libfreexl1 - library for direct reading of Microsoft Excel spreadsheets libfreexl1-dbg - library for direct reading of Mic

Accepted svgsalamander 0~svn95-1+deb7u1 (source all) into oldstable

2017-02-03 Thread Bas Couwenberg
Maintainers <pkg-java-maintain...@lists.alioth.debian.org> Changed-By: Bas Couwenberg <sebas...@debian.org> Description: libsvgsalamander-java - SVG engine for Java libsvgsalamander-java-doc - SVG engine for Java (documentation) Closes: 853134 Changes: svgsalamander (0~svn95-1+de

Re: Fixing CVE-2017-5522 (stack buffer overflow) for mapserver in wheezy

2017-01-19 Thread Bas Couwenberg
On 2017-01-19 10:27, Emilio Pozuelo Monfort wrote: On 19/01/17 08:14, Sebastiaan Couwenberg wrote: On 01/18/2017 10:17 PM, Ola Lundqvist wrote: Yes they are ok for wheezy-security. Thank you for your support. I've updated the secure-testing repo for this issue and sent the DLA. I haven't

Accepted mapserver 6.0.1-3.2+deb7u4 (source all amd64) into oldstable

2017-01-18 Thread Bas Couwenberg
: source all amd64 Version: 6.0.1-3.2+deb7u4 Distribution: wheezy-security Urgency: high Maintainer: Debian GIS Project <pkg-grass-de...@lists.alioth.debian.org> Changed-By: Bas Couwenberg <sebas...@debian.org> Description: cgi-mapserver - CGI executable for MapServer libmapscript

Re: Fixing CVE-2016-9839 for mapserver in wheezy

2016-12-07 Thread Bas Couwenberg
On 2016-12-07 09:49, Chris Lamb wrote: Sebastiaan Couwenberg wrote: Thanks, the fixed version has been uploaded, but the security-tracker marks it (6.0.1-3.2+deb7u3) as vulnerable which is incorrect. The security-tracker is generated from the files in the secure-testing repository, not from