Re: Anyone having more information about the tcpdump security CVEs?

2017-01-28 Thread Romain Francoise
Hi, On Fri, Jan 27, 2017 at 10:25:42PM +0100, Ola Lundqvist wrote: > Do anyone have any reference to something that I can have a look at to > judge whether this package need an update in wheezy or not. It definitively needs an update, however you should be aware that for jessie the DSA will just

Re: testing bind9 for Wheezy LTS

2017-01-28 Thread Guido Günther
Hi Thorsten, On Wed, Jan 25, 2017 at 10:19:36PM +0100, Thorsten Alteholz wrote: > Hi everybody, > > I uploaded version 9.8.4.dfsg.P1-6+nmu2+deb7u14 of bind9 to: > > https://people.debian.org/~alteholz/packages/wheezy-lts/bind9/amd64/ > > Please give it a try and tell me about any problems you

Re: Anyone having more information about the tcpdump security CVEs?

2017-01-28 Thread Ola Lundqvist
Hi Thank you for the information. How to upload and issue a DLA is available here: https://wiki.debian.org/LTS/Development I can issue the DLA if you do the upload. Are you sure the new tcpdump is backwards compatible? Best regards // Ola On 28 January 2017 at 09:56, Romain Francoise

Wheezy update of mysql-5.5?

2017-01-28 Thread Ola Lundqvist
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of mysql-5.5: https://security-tracker.debian.org/tracker/source-package/mysql-5.5 Would you like to take care of this yourself? If yes, please follow the workflow

Re: Wheezy update of calibre?

2017-01-28 Thread Antoine Beaupré
Just for the record: before packaging this update, we will need to investigate the issue much further. In particular, it seems likely that there are more undocumented but public security issues in Calibre. See for example bug #853004: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853004 But

Wheezy update of calibre?

2017-01-28 Thread Ola Lundqvist
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of calibre: https://security-tracker.debian.org/tracker/CVE-2010-1028 Would you like to take care of this yourself? If yes, please follow the workflow we have

Wheezy update of svgsalamander?

2017-01-28 Thread Ola Lundqvist
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of svgsalamander: https://security-tracker.debian.org/tracker/source-package/svgsalamander Would you like to take care of this yourself? If yes, please follow the