NEW changes in stable-new

2021-01-16 Thread Debian FTP Masters
Processing changes file: gnutls28_3.6.7-4+deb10u6_i386.changes ACCEPT

NEW changes in stable-new

2021-01-16 Thread Debian FTP Masters
Processing changes file: gnutls28_3.6.7-4+deb10u6_amd64.changes ACCEPT

NEW changes in stable-new

2021-01-16 Thread Debian FTP Masters
Processing changes file: gnutls28_3.6.7-4+deb10u6_armhf-buildd.changes ACCEPT

Bug#980268: buster-pu: cjson/1.7.10-1.1+deb10u1

2021-01-16 Thread Boyuan Yang
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Dear Release Team, I intend to fix https://bugs.debian.org/973442 in Buster. Under some circumstances, the user input will cause an infinite loop in libcjson library. This is a

Re: 10.8 planning

2021-01-16 Thread Cyril Brulebois
Adam D. Barratt (2021-01-16): > Please could you confirm your availability, and any preferences, for > the following: > > - January 30th (would mean we would have to freeze next weekend, so > a bit tight) > - February 6th > > My personal preference would be the 6th. Me too. But I can do both

Bug#980259: buster-pu: package cyrus-imapd/3.0.8-6+deb10u5

2021-01-16 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu [ Reason ] The /etc/cron.daily/cyrus-imapd cron script is not executed because the Cyrus version check does not match the cyrus version installed on Debian Buster [ Impact ] Dala

Bug#976811: transition: php8.0

2021-01-16 Thread Salvatore Bonaccorso
Hi, On Fri, Jan 15, 2021 at 07:58:10PM +0100, Ondřej Surý wrote: > Thinking about it, security-wise it might be better. Microsoft will > support the security backports to EOL versions of PHP 7.x, but they > announced they won’t do it for PHP 8.x, so we are (maybe) bit more > covered with PHP 7.4.

NEW changes in stable-new

2021-01-16 Thread Debian FTP Masters
Processing changes file: chromium_87.0.4280.141-0.1~deb10u1_source.changes ACCEPT Processing changes file: chromium_87.0.4280.141-0.1~deb10u1_all.changes ACCEPT Processing changes file: chromium_87.0.4280.141-0.1~deb10u1_amd64-buildd.changes ACCEPT Processing changes file:

Bug#979072: Bug#979047: RM: pepperflashplugin-nonfree -- RoQA; No longer work; upstream eol

2021-01-16 Thread Adam D. Barratt
On Fri, 2021-01-15 at 18:48 +0100, Andreas Beckmann wrote: > On Sat, 2 Jan 2021 22:09:07 +0800 Shengjing Zhu > wrote: > > On Sat, Jan 2, 2021 at 9:59 PM Adam D. Barratt < > > a...@adam-barratt.org.uk> wrote: > > > On Sat, 2021-01-02 at 19:53 +0800, Shengjing Zhu wrote: > > > > On Sat, Jan 2, 2021

Bug#976811: transition: php8.0

2021-01-16 Thread Moritz Mühlenhoff
Am Fri, Jan 15, 2021 at 07:58:10PM +0100 schrieb Ondřej Surý: > Thinking about it, security-wise it might be better. Microsoft will support > the security backports to EOL versions of PHP 7.x, but they announced they > won’t do it for PHP 8.x, so we are (maybe) bit more covered with PHP 7.4.

Bug#977520: buster-pu: package steam/1.0.0.59-4+deb10u1

2021-01-16 Thread Adam D. Barratt
Hi, Sorry for the delay in getting back to you. On Tue, 2020-12-15 at 23:36 +, Simon McVittie wrote: > Collect selected changes from unstable, in particular: > * Avoid redirecting stderr by default, which interferes with > upstream's > usual support/diagnostic process > * Add missing

Bug#959469: buster-pu: package openssl/1.1.1g-1

2021-01-16 Thread Kurt Roeckx
On Thu, Jan 14, 2021 at 09:13:49PM +0100, Sebastian Andrzej Siewior wrote: > On 2021-01-14 19:03:37 [+0100], Kurt Roeckx wrote: > > > Do you have pointers to upstream issues? > > > > There are a whole bunch of other issues and pull requests related to > > this. I hope this is the end of the

Processed: limit package to release.debian.org, forcibly merging 977028 941571

2021-01-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > limit package release.debian.org Limiting to bugs with field 'package' containing at least one of 'release.debian.org' Limit currently set to 'package':'release.debian.org' > forcemerge 977028 941571 Bug #977028 [release.debian.org] buster-pu:

Processed: Re: Bug#977028: buster-pu: package sane-backends/1.0.27-3.2

2021-01-16 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #977028 [release.debian.org] buster-pu: package sane-backends/1.0.27-3.2 Added tag(s) confirmed. -- 977028: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=977028 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#977028: buster-pu: package sane-backends/1.0.27-3.2

2021-01-16 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2020-12-10 at 09:44 +0100, Jörg Frings-Fürst wrote: > The udev rule to change the owner/group of usb scanners are not > included. > > [ Impact ] > Scanner working only as root > > [ Risks ] > Trivial. The same rule are included in older sane-backends

Processed: Re: Bug#977511: buster-pu: package edk2/0~20181115.85588389-3+deb10u2

2021-01-16 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #977511 [release.debian.org] buster-pu: package edk2/0~20181115.85588389-3+deb10u2 Added tag(s) confirmed. -- 977511: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=977511 Debian Bug Tracking System Contact ow...@bugs.debian.org with

Bug#977511: buster-pu: package edk2/0~20181115.85588389-3+deb10u2

2021-01-16 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2020-12-15 at 14:53 -0700, dann frazier wrote: > Address CVE-2019-14584 (#977300), for which the security team has > declined to > release a DSA. > Sorry for the delay. Please go ahead. Regards, Adam

Processed: Re: Bug#979724: buster-pu: package libmaxminddb/1.3.2-1+deb10u1

2021-01-16 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #979724 [release.debian.org] buster-pu: package libmaxminddb/1.3.2-1+deb10u1 Added tag(s) confirmed. -- 979724: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=979724 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#977735: buster-pu: package node-ini/1.3.5-1+deb10u1

2021-01-16 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2020-12-19 at 20:53 +0100, Xavier Guimard wrote: > node-ini is vulnearable to CVE-2020-7788: if an attacker submits a > malicious > INI file to an application that parses it with ini.parse, they will > pollute > the prototype on the application. This can be

Processed: Re: Bug#977735: buster-pu: package node-ini/1.3.5-1+deb10u1

2021-01-16 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #977735 [release.debian.org] buster-pu: package node-ini/1.3.5-1+deb10u1 Added tag(s) confirmed. -- 977735: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=977735 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#979724: buster-pu: package libmaxminddb/1.3.2-1+deb10u1

2021-01-16 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2021-01-10 at 21:39 +0200, Faidon Liambotis wrote: > This is an buster proposed update to fix CVE-2020-28241: > > libmaxminddb before 1.4.3 has a heap-based buffer over-read in > > dump_entry_data_list in maxminddb.c. > > The security team has marked the CVE

Bug#979749: buster-pu: package emacs/1:26.1+1-3.2+deb10u1

2021-01-16 Thread Adam D. Barratt
On Sun, 2021-01-10 at 20:08 -0600, Rob Browning wrote: > dkg has requested that we consider fixing this bug in buster: > > Debian: https://bugs.debian.org/919642 > Upstream: https://debbugs.gnu.org/34121 > > which is fairly straightforward (just the new patch at the end, > cherry-picked

Re: 10.8 planning

2021-01-16 Thread Laura Arjona Reina
Hi El 16 de enero de 2021 15:38:13 CET, "Adam D. Barratt" escribió: >Hi, > >It's that time again, when we should get 10.8 out. > >Please could you confirm your availability, and any preferences, for >the following: > >- January 30th (would mean we would have to freeze next weekend, so a >bit

Re: 10.8 planning

2021-01-16 Thread Andrew M.A. Cater
On Sat, Jan 16, 2021 at 02:38:13PM +, Adam D. Barratt wrote: > Hi, > > It's that time again, when we should get 10.8 out. > > Please could you confirm your availability, and any preferences, for > the following: > > - January 30th (would mean we would have to freeze next weekend, so a > bit

Bug#976094: buster-pu: package grub2/2.02+dfsg1-20+deb10u3

2021-01-16 Thread Adam D. Barratt
On Mon, 2021-01-11 at 15:57 +0100, Cyril Brulebois wrote: > Hi, > > Adam D. Barratt (2020-12-31): > > Sorry for the delay in picking this back up. > > Same here. > > > As grub produces udebs, this will need a KiBi-ack, so tagging and > > CCing accordingly. > > If I'm getting this right, the

Re: 10.8 planning

2021-01-16 Thread Steve McIntyre
Hey Adam, On Sat, Jan 16, 2021 at 02:38:13PM +, Adam Barratt wrote: >Hi, > >It's that time again, when we should get 10.8 out. > >Please could you confirm your availability, and any preferences, for >the following: > >- January 30th (would mean we would have to freeze next weekend, so a >bit

10.8 planning

2021-01-16 Thread Adam D. Barratt
Hi, It's that time again, when we should get 10.8 out. Please could you confirm your availability, and any preferences, for the following: - January 30th (would mean we would have to freeze next weekend, so a bit tight) - February 6th My personal preference would be the 6th. Cheers, Adam

Bug#979084: marked as done (transition: hamlib)

2021-01-16 Thread Debian Bug Tracking System
Your message dated Sat, 16 Jan 2021 09:19:51 +0100 with message-id and subject line Re: Bug#979084: transition: hamlib has caused the Debian Bug report #979084, regarding transition: hamlib to be marked as done. This means that you claim that the problem has been dealt with. If this is not the

Bug#979185: marked as done (transition: muparserx)

2021-01-16 Thread Debian Bug Tracking System
Your message dated Sat, 16 Jan 2021 09:19:27 +0100 with message-id and subject line Re: Bug#979185: transition: muparserx has caused the Debian Bug report #979185, regarding transition: muparserx to be marked as done. This means that you claim that the problem has been dealt with. If this is not