[Pkg-javascript-devel] Bug#760385: Fix for CVE-2014-5256

2014-12-20 Thread Balint Reczey
Hi Mike, On Fri, 19 Dec 2014 21:11:10 -0500 Michael Gilbert mgilb...@debian.org wrote: control: severity -1 important There is no security support for libv8 in jessie, so security issues aren't RC. Could you please add some links to explain that? I was about to fix this issue in an NMU

[Pkg-javascript-devel] Bug#760385: Fix for CVE-2014-5256

2014-12-20 Thread Michael Gilbert
On Sat, Dec 20, 2014 at 4:59 AM, Balint Reczey wrote: Hi Mike, On Fri, 19 Dec 2014 21:11:10 -0500 Michael Gilbert wrote: control: severity -1 important There is no security support for libv8 in jessie, so security issues aren't RC. Could you please add some links to explain that? I was

[Pkg-javascript-devel] Bug#760385: Fix for CVE-2014-5256

2014-12-20 Thread Jonas Smedegaard
Quoting Michael Gilbert (2014-12-20 03:11:10) control: severity -1 important There is no security support for libv8 in jessie, so security issues aren't RC. Lack of support do not change severity. Seems more appropriate to then tag as *-ignore instead. - Jonas -- * Jonas Smedegaard -

[Pkg-javascript-devel] Bug#760385: lowering severity of bugs not tracked by release team

2014-12-20 Thread Jonas Smedegaard
Quoting Michael Gilbert (2014-12-20 11:06:47) On Sat, Dec 20, 2014 at 4:59 AM, Balint Reczey wrote: On Fri, 19 Dec 2014 21:11:10 -0500 Michael Gilbert wrote: control: severity -1 important There is no security support for libv8 in jessie, so security issues aren't RC. Could you please add

[Pkg-javascript-devel] Bug#760385: lowering severity of bugs not tracked by release team

2014-12-20 Thread Jonas Smedegaard
[sent again, cc correct list address this time] Quoting Michael Gilbert (2014-12-20 11:06:47) On Sat, Dec 20, 2014 at 4:59 AM, Balint Reczey wrote: On Fri, 19 Dec 2014 21:11:10 -0500 Michael Gilbert wrote: control: severity -1 important There is no security support for libv8 in jessie, so

[Pkg-javascript-devel] Bug#760385: lowering severity of bugs not tracked by release team

2014-12-20 Thread Adam D. Barratt
On Sat, 2014-12-20 at 11:48 +0100, Jonas Smedegaard wrote: [sent again, cc correct list address this time] Quoting Michael Gilbert (2014-12-20 11:06:47) On Sat, Dec 20, 2014 at 4:59 AM, Balint Reczey wrote: On Fri, 19 Dec 2014 21:11:10 -0500 Michael Gilbert wrote: control: severity -1

[Pkg-javascript-devel] Bug#760385: Fix for CVE-2014-5256

2014-12-20 Thread Balint Reczey
Hi Mike, On Sat, 20 Dec 2014 05:06:47 -0500 Michael Gilbert mgilb...@debian.org wrote: On Sat, Dec 20, 2014 at 4:59 AM, Balint Reczey wrote: Hi Mike, On Fri, 19 Dec 2014 21:11:10 -0500 Michael Gilbert wrote: control: severity -1 important There is no security support for libv8 in

[Pkg-javascript-devel] Bug#760385: lowering severity of bugs not tracked by release team

2014-12-20 Thread Michael Gilbert
On Sat, Dec 20, 2014 at 6:15 AM, Adam D. Barratt wrote: On Sat, 2014-12-20 at 11:48 +0100, Jonas Smedegaard wrote: [sent again, cc correct list address this time] Quoting Michael Gilbert (2014-12-20 11:06:47) On Sat, Dec 20, 2014 at 4:59 AM, Balint Reczey wrote: On Fri, 19 Dec 2014

[Pkg-javascript-devel] Nieuwsbrief IO-dagaanbieding

2014-12-20 Thread DAGAANBIEDING
Voeg n...@io-dagaanbieding.nl toe aan je adressenboek om er zeker van te zijn dat je e-mails van IO-dagaanbieding zult ontvangen Uw Dagaanbieding vanzaterdag 20 december 2014 Deze week ook: Op IO Dagaanbieding vind u superdeals met kortingen tot wel 100 %! Elke dag weer een leuke,

[Pkg-javascript-devel] Processing of libv8-3.14_3.14.5.8-9_amd64.changes

2014-12-20 Thread Debian FTP Masters
libv8-3.14_3.14.5.8-9_amd64.changes uploaded successfully to localhost along with the files: libv8-3.14_3.14.5.8-9.dsc libv8-3.14_3.14.5.8-9.debian.tar.xz libv8-dev_3.14.5.8-9_amd64.deb libv8-3.14-dev_3.14.5.8-9_amd64.deb libv8-3.14.5_3.14.5.8-9_amd64.deb

[Pkg-javascript-devel] Bug#760385: lowering severity of bugs not tracked by release team

2014-12-20 Thread Bálint Réczey
Control: severity -1 grave Hi Mike, 2014-12-20 20:57 GMT+01:00 Michael Gilbert mgilb...@debian.org: On Sat, Dec 20, 2014 at 6:15 AM, Adam D. Barratt wrote: On Sat, 2014-12-20 at 11:48 +0100, Jonas Smedegaard wrote: [sent again, cc correct list address this time] Quoting Michael Gilbert

[Pkg-javascript-devel] Processed: Re: lowering severity of bugs not tracked by release team

2014-12-20 Thread Debian Bug Tracking System
Processing control commands: severity -1 grave Bug #760385 [libv8-3.14] nodejs: CVE-2014-5256 Severity set to 'grave' from 'important' -- 760385: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=760385 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

[Pkg-javascript-devel] Bug#773623: nodejs: CVE-2014-7192

2014-12-20 Thread Michael Gilbert
package: src:nodejs severity: important tags: security Hi, the following vulnerability was published for nodejs. CVE-2014-7192[0],[1]: | Eval injection vulnerability in index.js in the syntax-error package | before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application | Developer and