Re: Call for testing: upcoming xen security update

2017-11-10 Thread Hyacinthe Cartiaux
Hi, Quickly tested on a devel server (replica of our production set up), everything works: * paravirtualization mode only * 2 network bridges * pygrub * 2 domU under Jessie * 8 domU under Wheezy * 1 domU under Centos 7 Packages installed: * libxen-4.1_4.1.6.lts1-10~test2_amd64.deb *

Re: Call for testing: upcoming xen security update

2017-11-10 Thread Guido Günther
Hi Hyacinthe, On Fri, Nov 10, 2017 at 11:19:37AM +0100, Hyacinthe Cartiaux wrote: > Hi, > > Quickly tested on a devel server (replica of our production set up), > everything works: > > * paravirtualization mode only > * 2 network bridges > * pygrub > * 2 domU under Jessie > * 8 domU under Wheezy

Re: Bug#881110: cacti: CVE-2017-16641: arbitrary execution of os commands via path_rrdtool parameter in an action=save request

2017-11-10 Thread Paul Gevers
Control: found 881110 0.8.8a+dfsg-5+deb7u10 On 07-11-17 22:17, Salvatore Bonaccorso wrote: > Please adjust the affected versions in the BTS as needed, only did > check unstable's version for now source-wise. All versions in Debian are affected. Unfortunately the upstream commit contains much

RFC: Peculiar dependency change in graphicsmagick

2017-11-10 Thread Roberto C . Sánchez
Hello all, I have prepared an update for graphicsmagick (1.3.16-1.1+deb7u14) in wheezy. However, I have noted something very strange with the dependencies of the packages I built as compred to those of the previous version (1.3.16-1.1+deb7u13). Specifically, the graphicsmagick and

Re: RFC: Peculiar dependency change in graphicsmagick

2017-11-10 Thread Roberto C . Sánchez
On Fri, Nov 10, 2017 at 02:14:06PM -0500, Roberto C. Sánchez wrote: > > I would like to know what others think regarding this and whether I > should be concerned over the dependency changing between versions > liblcms1 -> liblcms2-2 -> liblcms1. > Please disregard. I have discussed this with

Re: RFC: Peculiar dependency change in graphicsmagick

2017-11-10 Thread Roberto C . Sánchez
On Fri, Nov 10, 2017 at 10:22:51PM +0100, Markus Koschany wrote: > > It's more like a handling error. When I use gbp like that: > > ARCH=amd64 git-buildpackage --git-dist=wheezy > > the build will fail in debian/rules line 31 because the > hardening-includes package does not exist in Sid

Re: RFC: Peculiar dependency change in graphicsmagick

2017-11-10 Thread Guido Günther
Hi, On Fri, Nov 10, 2017 at 04:29:09PM -0500, Roberto C. Sánchez wrote: > On Fri, Nov 10, 2017 at 10:22:51PM +0100, Markus Koschany wrote: > > > > It's more like a handling error. When I use gbp like that: > > > > ARCH=amd64 git-buildpackage --git-dist=wheezy > > > > the build will fail in

Accepted graphicsmagick 1.3.16-1.1+deb7u14 (source amd64 all) into oldoldstable

2017-11-10 Thread Roberto C. Sanchez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Fri, 10 Nov 2017 11:59:20 -0500 Source: graphicsmagick Binary: graphicsmagick libgraphicsmagick3 libgraphicsmagick1-dev libgraphicsmagick++3 libgraphicsmagick++1-dev libgraphics-magick-perl graphicsmagick-imagemagick-compat

Re: RFC: Peculiar dependency change in graphicsmagick

2017-11-10 Thread Chris Lamb
Hi, Well spotted! > Please disregard. I have discussed this with apo in IRC. Everything is > in order with the packages I built and I will be uploading them shortly. As I was curious, I checked IRC — for posterity and to save the rest of this list also looking it up: regarding

Re: RFC: Peculiar dependency change in graphicsmagick

2017-11-10 Thread Guido Günther
Hi apo, On Fri, Nov 10, 2017 at 08:17:33PM +, Chris Lamb wrote: > Hi, > > Well spotted! > > > Please disregard. I have discussed this with apo in IRC. Everything is > > in order with the packages I built and I will be uploading them shortly. > > As I was curious, I checked IRC — for

Re: RFC: Peculiar dependency change in graphicsmagick

2017-11-10 Thread Guido Günther
Hi Markus, On Fri, Nov 10, 2017 at 10:22:51PM +0100, Markus Koschany wrote: > Hi Guido, > > Am 10.11.2017 um 21:34 schrieb Guido Günther: > > Hi apo, > > On Fri, Nov 10, 2017 at 08:17:33PM +, Chris Lamb wrote: > >> Hi, > >> > >> Well spotted! > >> > >>> Please disregard. I have discussed

Re: RFC: Peculiar dependency change in graphicsmagick

2017-11-10 Thread Markus Koschany
Am 10.11.2017 um 22:29 schrieb Guido Günther: [...] > Assuming you're using pbuilder does > > git-buildpackage --git-dist=wheezy --git-arch=amd64 -nc > > work? Doh. Yes, that's it. I never thought about the clean target in this case because the include line is somewhere in no-man's-land.

[SECURITY] [DLA 1168-1] graphicsmagick security update

2017-11-10 Thread Roberto C . Sánchez
Package: graphicsmagick Version: 1.3.16-1.1+deb7u14 CVE ID : CVE-2017-16669 A remote denial of service vulnerability has been discovered in graphicsmagick, a collection of image processing tools and associated libraries. A specially crafted file can be used to produce a

Re: DLA for CVE-2017-8806/postgresql-common

2017-11-10 Thread Christoph Berg
Re: Salvatore Bonaccorso 2017-11-10 <20171110201118.wgv257pqulnzsdbg@eldamar.local> > Christoph Berg has uploaded a version for postgresql-common to address > CVE-2017-8806 as well for wheezy. > > https://lists.debian.org/debian-lts-changes/2017/11/msg00012.html > > If Christoph prefers to not

Re: RFC: Peculiar dependency change in graphicsmagick

2017-11-10 Thread Markus Koschany
Hi Guido, Am 10.11.2017 um 21:34 schrieb Guido Günther: > Hi apo, > On Fri, Nov 10, 2017 at 08:17:33PM +, Chris Lamb wrote: >> Hi, >> >> Well spotted! >> >>> Please disregard. I have discussed this with apo in IRC. Everything is >>> in order with the packages I built and I will be uploading

DLA for CVE-2017-8806/postgresql-common

2017-11-10 Thread Salvatore Bonaccorso
Hi Christoph Berg has uploaded a version for postgresql-common to address CVE-2017-8806 as well for wheezy. https://lists.debian.org/debian-lts-changes/2017/11/msg00012.html If Christoph prefers to not release the DLA himself, can a LTS team member release the DLA? Moritz's DSA text should