Bug#931610: stretch-pu: package pound/2.7-1.3+deb9u1

2019-08-22 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2019-08-22 at 11:51 +0200, Carsten Leonhardt wrote: [...] > longer testing revealed a regression (CPU load built up slowly, > finally reaching 100%). > > I found a fix and have applied it, the fixed version is running on > live servers since at least a week

Bug#931610: stretch-pu: package pound/2.7-1.3+deb9u1

2019-08-22 Thread Carsten Leonhardt
Control: tags -1 - confirmed Hi Adam, > On Sat, 2019-07-13 at 12:36 +0200, Carsten Leonhardt wrote: >> Control: tags -1 - moreinfo >> >> Hi, >> >> attached is a new debdiff, the only change is that I removed some >> cruft >> from the "Origin" field in the patch metadata. >> >> I've deployed

Bug#931610: stretch-pu: package pound/2.7-1.3+deb9u1

2019-08-20 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2019-07-13 at 12:36 +0200, Carsten Leonhardt wrote: > Control: tags -1 - moreinfo > > Hi, > > attached is a new debdiff, the only change is that I removed some > cruft > from the "Origin" field in the patch metadata. > > I've deployed this version on live

Bug#931610: stretch-pu: package pound/2.7-1.3+deb9u1

2019-07-13 Thread Carsten Leonhardt
Control: tags -1 - moreinfo Hi, attached is a new debdiff, the only change is that I removed some cruft from the "Origin" field in the patch metadata. I've deployed this version on live servers this morning and tested them. Also, the bug is now fixed in sid. Regards, Carsten diff -Nru

Bug#931610: stretch-pu: package pound/2.7-1.3+deb9u1

2019-07-08 Thread Carsten Leonhardt
Control: tags -1 - moreinfo > On 2019-07-08 09:40, Carsten Leonhardt wrote: >> pound is affected by non-dsa CVE-2016-10711. > > The metadata for #888786 indicates that the issue affects the package > in unstable, and is not yet fixed there. Is that correct? No, the package was removed from

Bug#931610: stretch-pu: package pound/2.7-1.3+deb9u1

2019-07-08 Thread Adam D. Barratt
Control: tags -1 + moreinfo On 2019-07-08 09:40, Carsten Leonhardt wrote: pound is affected by non-dsa CVE-2016-10711. The metadata for #888786 indicates that the issue affects the package in unstable, and is not yet fixed there. Is that correct? Regards, Adam

Bug#931610: stretch-pu: package pound/2.7-1.3+deb9u1

2019-07-08 Thread Carsten Leonhardt
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu pound is affected by non-dsa CVE-2016-10711. Attached is the diff, backported from pound 2.8a, same as the diff being used by SUSE. (c.f.