Missing libsndfile DLA announcement

2018-12-25 Thread Salvatore Bonaccorso
Hi Hugo, Just a heads up in case there was an issue in on sending the email (but I see as well not reserved DLA for it in data/DLA/list). Two days ago an update for src:libsndfile (1.0.25-9.1+deb8u2) reached the security archive but as per above I think neither a DLA was reserved nor a mail

Re: phpmyadmin / CVE-2018-19968

2018-12-25 Thread Abhijith PA
Hi Brian On Tuesday 18 December 2018 12:15 PM, Brian May wrote: > Sorry, somehow stuffed up the subject line. Meant to reference > CVE-2018-19968. > Are you working on phpmyadmin --a

Re: RFC: proposed fix for CVE-2018-19518 in uw-imap

2018-12-25 Thread Tomas Bortoli
Hi Robert, Your patch seems not to be definitive against CVE-2018-19518. This because checking for spaces won't be enough if an attacker uses some "bash trick" to get a space... In fact you can get a space by not typing it, with something like this: a=`date`;echo${a:3:1}asd Will print "asd".. it

Accepted libvncserver 0.9.9+dfsg2-6.1+deb8u4 (source amd64) into oldstable

2018-12-25 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Sun, 23 Dec 2018 16:21:23 +0530 Source: libvncserver Binary: libvncclient0 libvncserver0 libvncserver-dev libvncserver-config libvncclient0-dbg libvncserver0-dbg linuxvnc Architecture: source amd64 Version: 0.9.9+dfsg2-6.1+deb8u4