Is CVE-2014-0254 really affecting Qt and not only Windows?

2015-04-30 Thread Petter Reinholdtsen
Hi. debsecan just reported that one of my squeeze machines was affected by this one: CVE-2014-0254 The IPv6 implementation in Microsoft Windows 8,... http://security-tracker.debian.org/tracker/CVE-2014-0254 - libqtgui4, libqt4-sql-sqlite, libqt4-dev-bin, libqt4-sql, libqt4-declarative,

Re: Is CVE-2014-0254 really affecting Qt and not only Windows?

2015-04-30 Thread Raphael Hertzog
Hi Petter, On Thu, 30 Apr 2015, Petter Reinholdtsen wrote: But neither Redhat nor Ubuntu believe this CVE affect their software. Also NVD only list windows as affected. Are you sure Qt is affected by this CVE, or could there be a typo somewhere? It was indeed a typo. The qt4-x11 update I

Bug#783800: security-tracker: squeeze-lts/non-free not handled correctly

2015-04-30 Thread Raphaƫl Hertzog
Package: security-tracker Severity: important It looks like that squeeze-lts/non-free is not handled correctly. Have a look at jruby: $ rmadison jruby jruby | 1.5.1-1| oldoldstable/non-free | source, all jruby | 1.5.1-1+deb6u1 | buildd-squeeze-lts/non-free | source, all

Re: Is CVE-2014-0254 really affecting Qt and not only Windows?

2015-04-30 Thread Petter Reinholdtsen
[Raphael Hertzog] Hi Petter, Hi. :) Thanks for the notification! No worries. And thank you for clearing it up, removing one bug more from the list of bugs I need to worry about. :) PS: Next time please use debian-...@lists.debian.org for squeeze related issues (or at least put it in copy,

External check

2015-04-30 Thread Raphael Geissert
CVE-2015-3156: RESERVED -- The output might be a bit terse, but the above ids are known elsewhere, check the references in the tracker. The second part indicates the status of that id in the tracker at the moment the script was run. -- To UNSUBSCRIBE, email to