[Secure-testing-commits] r41758 - data/CVE

2016-05-16 Thread Brian May
Author: bam Date: 2016-05-16 07:32:51 + (Mon, 16 May 2016) New Revision: 41758 Modified: data/CVE/list Log: patch for this was included in wheezy update Modified: data/CVE/list === --- data/CVE/list 2016-05-16 06:54:33

[Secure-testing-commits] r41761 - data/DLA

2016-05-16 Thread Brian May
Author: bam Date: 2016-05-16 08:18:35 + (Mon, 16 May 2016) New Revision: 41761 Modified: data/DLA/list Log: Reserve DLA-477-1 for libidn Modified: data/DLA/list === --- data/DLA/list 2016-05-16 07:50:05 UTC (rev 41760) +

[Secure-testing-commits] r41763 - data

2016-05-16 Thread Brian May
) +++ data/dla-needed.txt 2016-05-16 08:46:37 UTC (rev 41763) @@ -41,10 +41,6 @@ -- libjackson-json-java -- -librsvg (Brian May) - Packages available for testing. - https://people.debian.org/~bam/debian/pool/main/libr/librsvg/ --- libspring-java The JSON/JaF doesn't appear to be prese

[Secure-testing-commits] r41821 - data/DLA

2016-05-17 Thread Brian May
Author: bam Date: 2016-05-17 22:37:22 + (Tue, 17 May 2016) New Revision: 41821 Modified: data/DLA/list Log: Reserve DLA-479-1 for xen Modified: data/DLA/list === --- data/DLA/list 2016-05-17 21:27:26 UTC (rev 41820) +++

[Secure-testing-commits] r41822 - data

2016-05-17 Thread Brian May
) +++ data/dla-needed.txt 2016-05-17 23:31:52 UTC (rev 41822) @@ -36,7 +36,7 @@ icu (Roberto C. Sánchez) NOTE: check comments on CVE-2016-0494 as well -- -imagemagick +imagemagick (Brian May) NOTE: several high profile vulnerabilities -- libjackson-json-java

[Secure-testing-commits] r41944 - in data: . DLA

2016-05-22 Thread Brian May
-needed.txt 2016-05-23 02:14:38 UTC (rev 41944) @@ -31,9 +31,6 @@ icu (Roberto C. Sánchez) NOTE: check comments on CVE-2016-0494 as well -- -imagemagick (Brian May) - NOTE: several high profile vulnerabilities --- libjackson-json-java -- libspring-java

[Secure-testing-commits] r42229 - data

2016-06-01 Thread Brian May
) +++ data/dla-needed.txt 2016-06-01 22:28:05 UTC (rev 42229) @@ -103,7 +103,7 @@ -- wordpress -- -xen +xen (Brian May) Update prepared by credativ ready here: https://people.debian.org/~zobel/xen-lts/ Just need review, upload and DLA. -- ___ Secure

[Secure-testing-commits] r42240 - data/CVE

2016-06-02 Thread Brian May
Author: bam Date: 2016-06-02 07:27:38 + (Thu, 02 Jun 2016) New Revision: 42240 Modified: data/CVE/list Log: No upstream fix for this Modified: data/CVE/list === --- data/CVE/list 2016-06-02 06:21:58 UTC (rev 42239) +++

[Secure-testing-commits] r42241 - data/CVE

2016-06-02 Thread Brian May
Author: bam Date: 2016-06-02 07:29:05 + (Thu, 02 Jun 2016) New Revision: 42241 Modified: data/CVE/list Log: Clarify wheezy is broken Modified: data/CVE/list === --- data/CVE/list 2016-06-02 07:27:38 UTC (rev 42240) +++

[Secure-testing-commits] r42242 - data

2016-06-02 Thread Brian May
) +++ data/dla-needed.txt 2016-06-02 07:33:15 UTC (rev 42242) @@ -61,7 +61,7 @@ NOTE: maintainer would like help working on the updates but will handle the updates himself NOTE: 20160518175636.ga29...@roeckx.be -- -p7zip +p7zip (Brian May) NOTE: CPP/7zip/Archive/Udf/UdfIn.cpp line 261

[Secure-testing-commits] r42386 - data

2016-06-07 Thread Brian May
) +++ data/dla-needed.txt 2016-06-07 22:15:23 UTC (rev 42386) @@ -30,7 +30,7 @@ icu (Roberto C. Sánchez) NOTE: check comments on CVE-2016-0494 as well -- -imagemagick +imagemagick (Brian May) -- libjackson-json-java -- ___ Secure-testing-commits

[Secure-testing-commits] r42436 - in data: . DLA

2016-06-10 Thread Brian May
@@ NOTE: fixed! Those checks should probably be added by cherry-picking NOTE: additional upstream changes. -- -p7zip (Brian May) - NOTE: CPP/7zip/Archive/Udf/UdfIn.cpp line 261? --- php5 (Thorsten Alteholz) -- qemu ___ Secure-testing-commits

[Secure-testing-commits] r42596 - data

2016-06-17 Thread Brian May
(rev 42595) +++ data/dla-needed.txt 2016-06-17 08:22:01 UTC (rev 42596) @@ -51,11 +51,12 @@ NOTE: maintainer would like help working on the updates but will handle the updates himself NOTE: 20160518175636.ga29...@roeckx.be -- -openssl +openssl (Brian May) NOTE: For CVE-2016-2177, some parts

[Secure-testing-commits] r42597 - in data: . DLA

2016-06-17 Thread Brian May
-17 08:30:00 UTC (rev 42597) @@ -30,8 +30,6 @@ icu (Roberto C. Sánchez) NOTE: check comments on CVE-2016-0494 as well -- -imagemagick (Brian May) --- libjackson-json-java -- libspring-java ___ Secure-testing-commits mailing list Secure-testing

[Secure-testing-commits] r42739 - data

2016-06-23 Thread Brian May
) +++ data/dla-needed.txt 2016-06-23 07:55:08 UTC (rev 42739) @@ -54,12 +54,13 @@ NOTE: maintainer would like help working on the updates but will handle the updates himself NOTE: 20160518175636.ga29...@roeckx.be -- -openssl (Brian May) +openssl NOTE: For CVE-2016-2177, some parts of the

[Secure-testing-commits] r42763 - data

2016-06-24 Thread Brian May
. -- -pidgin +pidgin (Brian May) -- php5 (Thorsten Alteholz) -- ___ Secure-testing-commits mailing list Secure-testing-commits@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits

[Secure-testing-commits] r42995 - in data: . DLA

2016-07-04 Thread Brian May
=== --- data/dla-needed.txt 2016-07-04 09:10:11 UTC (rev 42994) +++ data/dla-needed.txt 2016-07-04 09:31:29 UTC (rev 42995) @@ -81,8 +81,6 @@ -- phpmyadmin (Ola Lundqvist) -- -pidgin (Brian May) --- quagga NOTE: see dsa-needed's notes.

[Secure-testing-commits] r43006 - data

2016-07-04 Thread Brian May
) +++ data/dla-needed.txt 2016-07-05 06:51:33 UTC (rev 43006) @@ -11,7 +11,7 @@ -- asterisk (Thorsten Alteholz) -- -binutils +binutils (Brian May) -- binutils-h8300-hms -- ___ Secure-testing-commits mailing list Secure-testing-commits

[Secure-testing-commits] r43251 - in data: . DLA

2016-07-18 Thread Brian May
2016-07-18 06:47:05 UTC (rev 43250) +++ data/dla-needed.txt 2016-07-18 08:40:35 UTC (rev 43251) @@ -11,8 +11,6 @@ -- asterisk (Thorsten Alteholz) -- -binutils (Brian May) --- cacti (Emilio Pozuelo) NOTE: Maintainer wants to review changes; see https://lists.debian.org/<5724f47d.6

[Secure-testing-commits] r43482 - data/CVE

2016-07-26 Thread Brian May
Author: bam Date: 2016-07-26 08:57:04 + (Tue, 26 Jul 2016) New Revision: 43482 Modified: data/CVE/list Log: Temp CVE was fixed in wheezy LTS Modified: data/CVE/list === --- data/CVE/list 2016-07-26 06:29:30 UTC (rev 434

[Secure-testing-commits] r43736 - data

2016-08-03 Thread Brian May
) +++ data/dla-needed.txt 2016-08-03 08:34:13 UTC (rev 43736) @@ -98,7 +98,7 @@ -- tiff3 (Markus Koschany) -- -twisted +twisted (Brian May) NOTE: https://twistedmatrix.com/trac/ticket/8623 -- wireshark (Balint Reczey) ___ Secure-testing-commits

[Secure-testing-commits] r43886 - data/DLA

2016-08-09 Thread Brian May
Author: bam Date: 2016-08-09 08:32:56 + (Tue, 09 Aug 2016) New Revision: 43886 Modified: data/DLA/list Log: Reserve DLA-590-1 for python-django Modified: data/DLA/list === --- data/DLA/list 2016-08-09 08:11:00 UTC (rev 4

[Secure-testing-commits] r43906 - data/CVE

2016-08-10 Thread Brian May
Author: bam Date: 2016-08-10 07:57:30 + (Wed, 10 Aug 2016) New Revision: 43906 Modified: data/CVE/list Log: Make twisted-web no-dsa in wheezy Modified: data/CVE/list === --- data/CVE/list 2016-08-10 04:50:11 UTC (rev 43

[Secure-testing-commits] r43908 - data

2016-08-10 Thread Brian May
-08-10 07:58:31 UTC (rev 43907) +++ data/dla-needed.txt 2016-08-10 08:02:33 UTC (rev 43908) @@ -92,11 +92,6 @@ -- tiff3 (Markus Koschany) -- -twisted (Brian May) - NOTE: https://twistedmatrix.com/trac/ticket/8623 --- -twisted-web --- wireshark (Balint Reczey) -- wordpress

[Secure-testing-commits] r43978 - data/CVE

2016-08-15 Thread Brian May
Author: bam Date: 2016-08-15 08:20:09 + (Mon, 15 Aug 2016) New Revision: 43978 Modified: data/CVE/list Log: Add prerequisite patch for CVE-2015-8834 Modified: data/CVE/list === --- data/CVE/list 2016-08-14 10:57:58 UTC

[Secure-testing-commits] r44377 - data

2016-09-06 Thread Brian May
Author: bam Date: 2016-09-06 21:48:04 + (Tue, 06 Sep 2016) New Revision: 44377 Modified: data/dla-needed.txt Log: Remove matrixssl from dla-needed.txt As per email CABY6=0mdovum1vkzmxiau7rs5jysjv8mybinutz4fze11es...@mail.gmail.com Matrixssl is seldom used and only supports SSLv3. Also we

[Secure-testing-commits] r44515 - data

2016-09-11 Thread Brian May
) +++ data/dla-needed.txt 2016-09-11 22:18:10 UTC (rev 44515) @@ -11,7 +11,7 @@ -- asterisk (Thorsten Alteholz) -- -autotrace +autotrace (Brian May) NOTE: Reproducible with valgrind on Wheezy -- chicken ___ Secure-testing-commits mailing list Secure

[Secure-testing-commits] r44536 - data

2016-09-12 Thread Brian May
Author: bam Date: 2016-09-12 21:58:51 + (Mon, 12 Sep 2016) New Revision: 44536 Modified: data/dla-needed.txt Log: Add summary of my chicken research Modified: data/dla-needed.txt === --- data/dla-needed.txt 2016-09-12 21:10:1

[Secure-testing-commits] r44602 - in data: . DLA

2016-09-15 Thread Brian May
@@ -- asterisk (Thorsten Alteholz) -- -autotrace (Brian May) - NOTE: Reproducible with valgrind on Wheezy --- chicken NOTE: See report 87twdrpcyx@prune.linuxpenguins.xyz NOTE: Wheezy probably vulnerable however upstream patch is too invasive

[Secure-testing-commits] r44744 - data

2016-09-19 Thread Brian May
44743) +++ data/dla-needed.txt 2016-09-19 21:34:07 UTC (rev 44744) @@ -20,7 +20,7 @@ -- gcc-mingw-w64 (Stephen Kitt) -- -graphicsmagick +graphicsmagick (Brian May) -- icu (Roberto C. Sánchez) -- ___ Secure-testing-commits mailing list Secure-testing

<    1   2