Re: debsecan bugs about irssi

2018-03-26 Thread Ben Hutchings
because the patch for CVE-2018-7051 is missing from the uploaded source. Ben. -- Ben Hutchings When in doubt, use brute force. - Ken Thompson signature.asc Description: This is a digitally signed message part

Re: Better communication about spectre/meltdown

2018-03-19 Thread Ben Hutchings
On Fri, 2018-03-09 at 02:05 +, Ben Hutchings wrote: > On Sat, 2018-03-03 at 20:40 +0000, Ben Hutchings wrote: > > On Sat, 2018-03-03 at 11:07 -0500, Roberto C. Sánchez wrote: > > > On Sat, Mar 03, 2018 at 03:22:14PM +0000, Ben Hutchings wrote: > > > > > >

Re: tiff / CVE-2018-7456

2018-03-15 Thread Ben Hutchings
hen defining td->td_samplesperpixel, > in order to make this inconsistent state impossible ? Yes. Ben. > (Please correct me if I'm wrong !) > > Hope this helps ! :) -- Ben Hutchings Quantity is no substitute for quality, but it's the only one we've got. signature.asc Description: This is a digitally signed message part

Re: Better communication about spectre/meltdown

2018-03-08 Thread Ben Hutchings
On Sat, 2018-03-03 at 20:40 +, Ben Hutchings wrote: > On Sat, 2018-03-03 at 11:07 -0500, Roberto C. Sánchez wrote: > > On Sat, Mar 03, 2018 at 03:22:14PM +0000, Ben Hutchings wrote: > > > > > > I think that backporting gcc-4.9 and building the kernel with it (for &g

Re: Better communication about spectre/meltdown

2018-03-03 Thread Ben Hutchings
On Sat, 2018-03-03 at 11:07 -0500, Roberto C. Sánchez wrote: > On Sat, Mar 03, 2018 at 03:22:14PM +0000, Ben Hutchings wrote: > > > > I think that backporting gcc-4.9 and building the kernel with it (for > > x86) is lower risk than backporting the retpoline patches to gcc

Re: Better communication about spectre/meltdown

2018-03-03 Thread Ben Hutchings
On Thu, 2018-03-01 at 07:56 -0500, Roberto C. Sánchez wrote: > On Mon, Feb 26, 2018 at 11:06:03PM +0000, Ben Hutchings wrote: > > > > It will almost certainly build correctly with 4.9 on x86. AIUI the > > Spectre mitigations in gcc are x86-specific, so there's no value in &g

Re: Better communication about spectre/meltdown

2018-02-26 Thread Ben Hutchings
hanging it for ARM and there would be a risk of exceeding code size limits on armel. The kernel package already has provision for using different compiler versions per-architecture. Ben. > Note that only the 4.9.x series has seen upstream releases in the last > ~3 years. The last 4.7 relea

Re: current status of spectre/meltdown

2018-02-24 Thread Ben Hutchings
SER backports we are using in all our stable branches (wheezy, jessie and stretch) map all kernel stack pages in the user-space page tables. This is a significant weakness that ought to be fixed. In 4.14+, only small per-CPU entry stacks (and other essential data) are included in the user-space page

Re: upload leptonlib

2018-02-22 Thread Ben Hutchings
On Thu, 2018-02-22 at 07:26 +0100, Salvatore Bonaccorso wrote: > Hi Ben, > > On Sat, Feb 17, 2018 at 09:28:19PM +0000, Ben Hutchings wrote: > > On Fri, 2018-02-16 at 14:36 -0500, Antoine Beaupré wrote: > > > On 2018-02-15 21:34:48, Ben Hutchings wrote: > > > &g

Re: Better communication about spectre/meltdown

2018-02-17 Thread Ben Hutchings
). > > For the architectures supported in LTS the compiler difference > between 4.6 and 4.9 should not matter. I hope so, but that's quite a large jump. Won't we also rebuild firefox-esr and xen with retpoline? Ben. -- Ben Hutchings It is easier to change the specification to fit the progr

Re: upload leptonlib

2018-02-17 Thread Ben Hutchings
On Fri, 2018-02-16 at 14:36 -0500, Antoine Beaupré wrote: > On 2018-02-15 21:34:48, Ben Hutchings wrote: > > On Wed, 2018-02-14 at 22:23 -0500, Roberto C. Sánchez wrote: > > > On Wed, Feb 14, 2018 at 02:56:24PM +0530, Abhijith PA wrote: > > > > Hello. > >

Re: upload leptonlib

2018-02-15 Thread Ben Hutchings
/ptab.pta /tmp/smooth/boxae.ba /tmp/smooth/boxao.ba /tmp/smooth/boxalfe.ba /tmp/smooth/boxalfo.ba /tmp/smooth/boxame.ba /tmp/smooth/boxamo.ba /tmp/smooth/boxamede.ba /tmp/smooth/boxamedo.ba ... Ben. > In any event, once you receive the ACCEPT notice from the archive > software you shou

Re: [SECURITY] [DLA 1232-1] linux security update - hidepid not working in Wheezy (regression)

2018-01-25 Thread Ben Hutchings
hidepid=2 from > fstab and rebooting. [...] This is bug #887106 and will be fixed in the next update. Ben. -- Ben Hutchings Unix is many things to many people, but it's never been everything to anybody. signature.asc Description: This is a digitally signed message part

Re: pulling in other vulnerability databases

2018-01-25 Thread Ben Hutchings
fixes in Linux actually get CVE IDs. Ben. -- Ben Hutchings Unix is many things to many people, but it's never been everything to anybody. signature.asc Description: This is a digitally signed message part

Re: Wheezy update of poco?

2018-01-09 Thread Ben Hutchings
a macro. Will > continue this evening. > > Cheers Jochen -- Ben Hutchings If at first you don't succeed, you're doing about average. signature.asc Description: This is a digitally signed message part

Accepted linux-latest 46+deb7u1 (all source) into oldoldstable

2018-01-07 Thread Ben Hutchings
: high Maintainer: Debian Kernel Team <debian-ker...@lists.debian.org> Changed-By: Ben Hutchings <b...@decadent.org.uk> Description: linux-doc-2.6 - Linux kernel specific documentation (dummy package) linux-doc - Linux kernel specific documentation (meta-package) linux-headers-2.6-

Accepted linux 3.2.96-3 (all source) into oldoldstable, oldoldstable

2018-01-06 Thread Ben Hutchings
linux-image-3.2.0-5-sparc64-smp linux-headers-3.2.0-5-sparc64-smp linux-headers-3.2.0-5-all-sparc64 Architecture: all source Version: 3.2.96-3 Distribution: wheezy-security Urgency: high Maintainer: Debian Kernel Team <debian-ker...@lists.debian.org> Changed-By: Ben Hutchi

[SECURITY] [DLA 1200-1] linux security update

2017-12-10 Thread Ben Hutchings
how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams signature.asc Description: This is a digitally signed message part

Accepted linux 3.2.96-2 (all source) into oldoldstable

2017-12-10 Thread Ben Hutchings
linux-image-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-all-sparc64 Architecture: all source Version: 3.2.96-2 Distribution: wheezy-security Urgency: high Maintainer: Debian Kernel Team <debian-ker...@lists.debian.org> Changed-By: Ben Hutchi

Accepted linux 3.2.96-1 (all source) into oldoldstable

2017-12-09 Thread Ben Hutchings
linux-image-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-all-sparc64 Architecture: all source Version: 3.2.96-1 Distribution: wheezy-security Urgency: high Maintainer: Debian Kernel Team <debian-ker...@lists.debian.org> Changed-By: Ben Hutchi

Re: Debian Jessie

2017-10-11 Thread Ben Hutchings
hich uses a new archive suite and required adding a line to APT sources.list. Wheezy LTS does not require this - it uses the same suite as for regular security support. I would expect the same to be true for Jessie LTS. Ben. -- Ben Hutchings Man invented language to satisfy his deep need to complain

Re: Call for testing: dnsmasq security update

2017-10-07 Thread Ben Hutchings
e changes reviewed by the upstream (and Debian) maintainer, and uploaded the update to wheezy-security yesterday. Ben. -- Ben Hutchings Humans are not rational beings; they are rationalising beings. signature.asc Description: This is a digitally signed message part

Accepted dnsmasq 2.62-3+deb7u4 (all source) into oldoldstable

2017-10-06 Thread Ben Hutchings
;si...@thekelleys.org.uk> Changed-By: Ben Hutchings <b...@decadent.org.uk> Description: dnsmasq-base - Small caching DNS proxy and DHCP/TFTP server dnsmasq- Small caching DNS proxy and DHCP/TFTP server dnsmasq-utils - Utilities for manipulating DHCP leases Changes: dnsmasq (2.62-3+deb7u4) whe

Re: Call for testing: dnsmasq security update

2017-10-05 Thread Ben Hutchings
On Thu, 2017-10-05 at 19:33 +0200, Guido Günther wrote: > Hi Ben, > On Thu, Oct 05, 2017 at 05:31:09PM +0100, Ben Hutchings wrote: > > I've prepared a security update for dnsmasq in wheezy, fixing the > > relevant CVEs: > > > > * CVE-2017-14491: DNS heap buffer o

Call for testing: dnsmasq security update

2017-10-05 Thread Ben Hutchings
ezy-security/>. Ben. -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams signature.asc Description: This is a digitally signed message part

[SECURITY] [DLA 1099-1] linux security update

2017-09-20 Thread Ben Hutchings
ates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams signature.asc Description: This is a digitally signed message part

Accepted linux 3.2.93-1 (all source) into oldoldstable

2017-09-18 Thread Ben Hutchings
linux-image-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-all-sparc64 Architecture: all source Version: 3.2.93-1 Distribution: wheezy-security Urgency: high Maintainer: Debian Kernel Team <debian-ker...@lists.debian.org> Changed-By: Ben Hutchi

Re: Need to upgrade to jessie need help

2017-07-26 Thread Ben Hutchings
On Wed, 2017-07-26 at 14:46 +, Vigneshdhanraj G1 wrote: > Thanks Ben,  > > Actually I am using wheezy with kernel 3.2.x not the one which debian > gives. So I thought of upgrading to Jessie with same kernel. [...] Upstream support for 3.2 also ends at the end of May 2018. B

[SECURITY] [DLA 993-2] linux regression update

2017-06-27 Thread Ben Hutchings
frequently asked questions can be found at: https://wiki.debian.org/LTS -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams signature.asc Description: This is a digitally signed message part

Re: Wheezy update of unrar-nonfree?

2017-06-26 Thread Ben Hutchings
at wheezy is new enough to run it. Ben. -- Ben Hutchings Never put off till tomorrow what you can avoid all together. signature.asc Description: This is a digitally signed message part

[SECURITY] [DLA 993-1] linux security update

2017-06-19 Thread Ben Hutchings
estions can be found at: https://wiki.debian.org/LTS -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams signature.asc Description: This is a digitally signed message part

Accepted linux 3.2.89-1 (all source) into oldoldstable

2017-06-19 Thread Ben Hutchings
linux-image-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-all-sparc64 Architecture: all source Version: 3.2.89-1 Distribution: wheezy-security Urgency: high Maintainer: Debian Kernel Team <debian-ker...@lists.debian.org> Changed-By: Ben Hutchi

[SECURITY] [DLA 970-1] sudo security update

2017-05-30 Thread Ben Hutchings
;, this problem has been fixed in version 1.8.10p3-1+deb8u4. We recommend that you upgrade your sudo packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- Ben Hutchi

Accepted sudo 1.8.5p2-1+nmu3+deb7u3 (amd64 source) into oldstable

2017-05-30 Thread Ben Hutchings
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Tue, 30 May 2017 22:20:15 +0100 Source: sudo Binary: sudo sudo-ldap Architecture: amd64 source Version: 1.8.5p2-1+nmu3+deb7u3 Distribution: wheezy-security Urgency: high Maintainer: Bdale Garbee <bd...@gag.com> Changed-B

Re: Accepted libpodofo 0.9.0-1.1+deb7u1 (source amd64) into oldstable

2017-05-03 Thread Ben Hutchings
ect* inObject, int depth ) const; ... +const PdfObject* PdfPage::GetInheritedKeyFromObject( const char* inKey, const PdfObject* inObject ) const +{ +return GetInheritedKeyFromObject(inKey, inObject, 0); +} Ben. -- Ben Hutchings friends: People who know you well, but like you anyway. signature.asc Description: This is a digitally signed message part

[SECURITY] [DLA 922-1] linux security update

2017-04-28 Thread Ben Hutchings
hat you upgrade your linux packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams signa

Accepted linux 3.2.88-1 (all source) into oldstable

2017-04-27 Thread Ben Hutchings
linux-image-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-all-sparc64 Architecture: all source Version: 3.2.88-1 Distribution: wheezy-security Urgency: high Maintainer: Debian Kernel Team <debian-ker...@lists.debian.org> Changed-By: Ben Hutchi

Re: CVE-2016-8685 in potrace

2017-04-03 Thread Ben Hutchings
relies on two's-complement wrapping behaviour on signed arithmetic, which is -fwrapv. See also the -fno-strict-overflow option. Ben. -- Ben Hutchings Humans are not rational beings; they are rationalising beings. signature.asc Description: This is a digitally signed message part

Re: dead changelog link on debian kernel site

2017-03-10 Thread Ben Hutchings
leases, all uploads accepted by security.debian.org are also copied to ftp- master.debian.org and the changelog is published shortly afterward. Since wheezy will not have any more point releases, this process has been disabled for wheezy-security. *All* updates to wheezy-security now have the exact

[SECURITY] [DLA 849-1] linux security update

2017-03-09 Thread Ben Hutchings
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams signature.asc Description: This is a digitally signed message part

Re: Wheezy update of texlive-base?

2017-03-08 Thread Ben Hutchings
h parameter "vsyscall=emulate" in order to > make the Wheezy chroot work again. > > Cheers, >  jonas > > [1] https://lists.debian.org/debian-kernel/2016/11/msg00303.html > > -- Ben Hutchings All extremists should be taken out and shot. signature.asc Description: This is a digitally signed message part

Accepted linux 3.2.86-1 (all source) into oldstable

2017-03-08 Thread Ben Hutchings
linux-image-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-sparc64-smp linux-headers-3.2.0-4-all-sparc64 Architecture: all source Version: 3.2.86-1 Distribution: wheezy-security Urgency: high Maintainer: Debian Kernel Team <debian-ker...@lists.debian.org> Changed-By: Ben Hutchi

Accepted wireless-regdb 2016.06.10-1~deb7u1 (all source) into oldstable

2017-01-15 Thread Ben Hutchings
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 12 Jan 2017 23:15:13 + Source: wireless-regdb Binary: wireless-regdb Architecture: all source Version: 2016.06.10-1~deb7u1 Distribution: wheezy-security Urgency: medium Maintainer: Ben Hutchings <b...@decadent.org

Re: ipv6 routing memory leak

2017-01-05 Thread Ben Hutchings
h IPv6 in Linux 3.2. It is unlikely to be possible to fix them all with backported fixes. Ben. -- Ben Hutchings The generation of random numbers is too important to be left to chance. - Robert Coveyou signature.asc Description: This is a digitally signed message part

[SECURITY] [DLA 772-1] linux security update

2017-01-01 Thread Ben Hutchings
ed in the next point release (8.6). We recommend that you upgrade your linux packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- Ben Hutchings - Debian develop

Re: using existing workflows?

2016-12-19 Thread Ben Hutchings
> wonder how many of those we can efficiently keep in our heads at > once. :) > > A. > -- Ben Hutchings Beware of programmers who carry screwdrivers. - Leonard Brandwein signature.asc Description: This is a digitally signed message part

Re: RFC - ImageMagick, proper testing, and handling issues without a CVE ID

2016-11-30 Thread Ben Hutchings
cker.debian.org/tracker/CVE-- ? Ben. -- Ben Hutchings A free society is one where it is safe to be unpopular. - Adlai Stevenson signature.asc Description: This is a digitally signed message part

Re: Avice about the importance of heap overflow in hdf5

2016-11-24 Thread Ben Hutchings
ries that use their own heap.) I've previously been told that this makes it impractical to achieve code execution through a heap overflow. Ben. -- Ben Hutchings [W]e found...that it wasn't as easy to get programs right as we had thought. ... I realized that a large part of my life from then on was g

Re: linux-image-3.2.0-4-486

2016-11-13 Thread Ben Hutchings
On Sun, 2016-11-13 at 13:17 +0100, Miroslav Skoric wrote: > On 11/13/2016 04:58 AM, Ben Hutchings wrote: > > > > > I'm afraid this hasn't arrived.  Maybe reportbug doesn't know how to > > send mail from your system?  There should still be a file in /tmp (name >

Re: linux-image-3.2.0-4-486

2016-11-12 Thread Ben Hutchings
On Sun, 2016-11-06 at 17:45 +0100, Miroslav Skoric wrote: > On 11/05/2016 10:37 PM, Ben Hutchings wrote: > > > > > Please use 'reportbug kernel' to open a bug report and attach the file > > to the report. > > > > Done. I'm afraid this hasn't arrived. Mayb

Re: python-django and CVE-2016-9014

2016-11-10 Thread Ben Hutchings
Generated a random database user password when running > +tests on Oracle. [...] That's not the issue being patched. Ben. -- Ben Hutchings Q.  Which is the greater problem in the world today, ignorance or apathy? A.  I don't know and I couldn't care less. signature.asc Description: This is a digitally signed message part

Re: linux-image-3.2.0-4-486

2016-11-05 Thread Ben Hutchings
On Sat, 2016-11-05 at 14:03 +0100, Miroslav Skoric wrote: > On 11/04/2016 09:58 PM, Ben Hutchings wrote: > > > > > You should be able to extract the kernel log messages for the new > > kernel version like this: > > > > { zcat /var/log/messages.{4,3,

Re: CVE-2016-9013 / django-python

2016-11-03 Thread Ben Hutchings
security advisory.  So far as I can see, the old behaviour: - is not triggered by normal usage, and cannot be triggered by a   malicious user - is documented, and can be overridden:   <https://sources.debian.net/src/python-django/1.4.5-1%2Bdeb7u16/docs/ref/settings.txt/#L669> Ben. -- Ben

Re: Regression problem, call for advice Re: Call for advice and testing of nss (and nspr) and intention to upload correction

2016-11-02 Thread Ben Hutchings
..] I don't think we've specifically discussed this yet.  That's what is happening now. Ben. -- Ben Hutchings The world is coming to an end. Please log off. signature.asc Description: This is a digitally signed message part

Re: Regression problem, call for advice Re: Call for advice and testing of nss (and nspr) and intention to upload correction

2016-11-01 Thread Ben Hutchings
system library. > 2) Is this severe enough for me to revert the nss 3.26 upload? [...] If *only* the outdated Debian package of chromium is affected, then obviously I don't think it is. Ben. -- Ben Hutchings Horngren's Observation:    Among economists, the real world

Re: Call for advice and testing of nss (and nspr) and intention to upload correction

2016-11-01 Thread Ben Hutchings
sts.debian.org/debian-security-announce/2015/msg00031.html [...] What would be the point?  Anyone using chromium on wheezy should have upgraded already. Ben. --  Ben Hutchings Horngren's Observation:    Among economists, the real world is often a special case. sign

[SECURITY] [DLA 670-1] linux security update

2016-10-19 Thread Ben Hutchings
/wiki.debian.org/LTS -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams signature.asc Description: This is a digitally signed message part

Re: systemd CVE-2016-7796

2016-10-09 Thread Ben Hutchings
On Mon, 2016-10-10 at 08:09 +1100, Brian May wrote: > Ben Hutchings <b...@decadent.org.uk> writes: > > > Oh, I didn't realise that.  Let's drop those then. > > > > This patch also needs to change the '<= 0' to '< 0', doesn't it? > > &g

Re: systemd CVE-2016-7796

2016-10-07 Thread Ben Hutchings
On Fri, 2016-10-07 at 17:52 +1100, Brian May wrote: > > Ben Hutchings <b...@decadent.org.uk> writes: > > > > It looks like this patch does three things > > > > > > * It removes "assert(n > 0)". > > > > > > * It removes

Re: systemd CVE-2016-7796

2016-10-06 Thread Ben Hutchings
On Fri, 2016-10-07 at 08:10 +1100, Brian May wrote: > Ben Hutchings <b...@decadent.org.uk> writes: > > > 2. Fix for CVE-2016-7796 > > > Has undefined reference to IN_SET. > > I am guessing I don't need this part of the patch, right? > > - 

Re: systemd CVE-2016-7796

2016-10-05 Thread Ben Hutchings
f n < 0 as an error 2. Fix for CVE-2016-7796 3. If-the-notification-message-length-is-0-ignore-the-messag.patch 4. pid1-process-zero-length-notification-messages-again.patch Ben. -- Ben Hutchings Sturgeon's Law: Ninety percent of everything is crap. signature.asc Description: This is a dig

Re: systemd CVE-2016-7796

2016-10-05 Thread Ben Hutchings
 assert((size_t) n < sizeof(buf)); >  buf[n] = 0; >  if (!(tags = strv_split(buf, "\n\r"))) > -return -ENOMEM; > +return 0; >   >  log_debug("Got notification message for unit %s", u->id); > > I have not yet claimed systemd yet, if somebody else wants to claim it > before I do, go ahead. -- Ben Hutchings Sturgeon's Law: Ninety percent of everything is crap. signature.asc Description: This is a digitally signed message part

Re: boot problem after updating dropbear [solved -- MANUAL initrd works required]

2016-09-26 Thread Ben Hutchings
te your changes.  That would not be a bug since it's not a configuration file. You'll need to write a *separate* hook script that installs the extra files. Ben. -- Ben Hutchings In a hierarchy, every employee tends to rise to his level of incompetence. signature.asc Description: This is a digitally signed message part

Re: autotrace CVE-2016-7392

2016-09-11 Thread Ben Hutchings
toedit_suffix_table, sizeof(char *) * (2 * (dd_tmp - dd_start) + 1)); ^ ^ Ben. -- Ben Hutchings Klipstein's 4th Law of Prototyping and Production: A fail-safe circuit will destroy others. signature.asc Description: This is a digitally signed message part

Re: Wheezy update of inspircd?

2016-09-07 Thread Ben Hutchings
e upstream version). Ben. > It's only because I requested those CVEs that this issue propped up on > Debian's radar at all, btw... > > A. -- Ben Hutchings For every action, there is an equal and opposite criticism. - Harrison signature.asc Description: This is a digitally signed message part

Re: matrixssl

2016-09-06 Thread Ben Hutchings
On Wed, 2016-09-07 at 07:38 +1000, Brian May wrote: > > Ben Hutchings <b...@decadent.org.uk> writes: > > > > > So let's add it to the unsupported packages list. > > Sounds like a good idea. Not sure we really should be supporting > encryption libraries tha

Re: matrixssl

2016-09-06 Thread Ben Hutchings
gt; in data/CVE/list. No, that only means it was removed from unstable. Ben. -- Ben Hutchings For every action, there is an equal and opposite criticism. - Harrison signature.asc Description: This is a digitally signed message part

Re: matrixssl

2016-09-05 Thread Ben Hutchings
?id=7664#c4 > > Thanks for this. Finally got it working... > > ...BUT matrixssl is SSLv3 only. [...] So let's add it to the unsupported packages list. Ben. -- Ben Hutchings I haven't lost my mind; it's backed up on tape somewhere. signature.asc Description: This is a digitally signed message part

[SECURITY] [DLA 609-1] linux security update

2016-09-03 Thread Ben Hutchings
dates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams signature.asc Description: This is a digitally signed message part

CVE request: Kernel Oops when issuing fcntl on an AUFS directory

2016-08-30 Thread Ben Hutchings
<+234>:   callq  *0xd0(%r14) > 0x81108701 <+241>:   test   %eax,%eax > #v- > > Naturally it happens both on i686 and amd64. > > BTW, changelog link on the package's page[1] is dead. > > Interesting changelog's part: > >   * aufs: Make fcntl(F_S

Re: Kernel Oops when issuing fcntl on an AUFS directory

2016-08-30 Thread Ben Hutchings
t;i_fop = _dir_fop; > #v- > > The aufs_file_fop structure sets the value of the .setfl member to > aufs_setfl (f_op.c). aufs_dir_fop (dir.c) on the other hand does not. Thanks for finding this; I'll fix it. [...] > BTW, changelog link on the package's page[1] is dead. [...] This is unfo

Re: Wheezy update of mingw-w64?

2016-08-27 Thread Ben Hutchings
ould be similar. If that's OK with you, let me know and I'll assign myself > the dla-needed.txt entry (along with mingw32 which will use the same fix). This isn't very urgent.  Just make sure to check and update dla-needed.txt before you start work. Ben. -- Ben Hutchings [W]e found...that i

Re: [SECURITY] [DLA 588-1] mongodb security update

2016-08-08 Thread Ben Hutchings
ogging. > > CVE-2016-6494 >   World-readable .dbshell history file > > TEMP-0833087-C5410D >   Bruteforcable challenge responses in unprotected logfile [...] This temporary ID is not stable and shouldn't be used in a DLA or DSA. The Debian bug number, which you already included, i

Re: Analysis of issue for phpmyadmin and request for comment on XSS issues

2016-06-26 Thread Ben Hutchings
y DBAs are going to turn Javascript off *and* check every link target before following it. However, I think XSS issues are generally treated as not meriting a DSA/DLA by themselves. Ben. -- Ben Hutchings Humour is the best antidote to reality. signature.asc Description: This is a digitally signed message part

Re: changelogs missing!

2016-06-19 Thread Ben Hutchings
kages that only exist in the security archive are not available from that server.  Since the last point release for wheezy, uploads to wheezy-security (for LTS) are not being copied to the main archive and so their changelogs are never available from there. Ben. -- Ben Hutchings Never put off til

Re: Wheezy update of qemu?

2016-06-13 Thread Ben Hutchings
On Mon, 2016-06-13 at 20:28 +0300, Michael Tokarev wrote: > 13.06.2016 19:55, Ben Hutchings wrote: > > On Mon, 2016-06-13 at 18:23 +0300, Michael Tokarev wrote: > > > 06.06.2016 04:37, Ben Hutchings wrote: > > > > Hello dear maintainer(s), > > > > >

Re: Wheezy update of qemu?

2016-06-13 Thread Ben Hutchings
On Mon, 2016-06-13 at 18:23 +0300, Michael Tokarev wrote: > 06.06.2016 04:37, Ben Hutchings wrote: > > Hello dear maintainer(s), > > > > the Debian LTS team would like to fix the security issues which are > > currently open in the Wheezy version of qemu: > > ht

Wheezy update of qemu-kvm?

2016-06-05 Thread Ben Hutchings
or not. If you don't want to take care of this update, it's not a problem, we will do our best with your package. Just let us know whether you would like to review and/or test the updated package before it gets released. Thank you very much. Ben Hutchings,   on behalf of the Debian LTS team. PS

Wheezy update of expat?

2016-06-05 Thread Ben Hutchings
us know whether you would like to review and/or test the updated package before it gets released. Thank you very much. Ben Hutchings,   on behalf of the Debian LTS team. PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone

Re: HFS+ specific vulnerability

2016-06-03 Thread Ben Hutchings
On Fri, 2016-06-03 at 17:25 +1000, Brian May wrote: > Ben Hutchings <b...@decadent.org.uk> writes: > > > [ Unknown signature status ] > > On Thu, 2016-06-02 at 17:39 +1000, Brian May wrote: > > > Hello, > > > > > > Do we care about vulerabi

Re: HFS+ specific vulnerability

2016-06-02 Thread Ben Hutchings
mat is part of its attack surface.  I don't think we can rule out certain formats as too obscure.  (See for example the recent attacks on ImageMagick/GraphicsMagick using a format that most people never heard of before.  The fix there was to disable support for that format by default.) Ben. --

Wheezy update of dhcpcd5?

2016-05-31 Thread Ben Hutchings
let us know whether you would like to review and/or test the updated package before it gets released. Thank you very much. Ben Hutchings,   on behalf of the Debian LTS team. PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone

Wheezy update of libpdfbox-java?

2016-05-31 Thread Ben Hutchings
and/or test the updated package before it gets released. Thank you very much. Ben Hutchings,   on behalf of the Debian LTS team. PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone is registered on this update in this file: https

Re: Supporting armel/armhf in wheezy-lts

2016-04-25 Thread Ben Hutchings
ove to a bounty model for working on LTS. [...] I seriously doubt my employer would let me work on LTS on this basis. Ben. -- Ben Hutchings All the simple programs have been written, and all the good names taken. signature.asc Description: This is a digitally signed message part

Re: Supporting armel/armhf in wheezy-lts

2016-04-24 Thread Ben Hutchings
On Sun, 2016-04-24 at 22:24 +0200, Ben Hutchings wrote: > On Mon, 2016-04-18 at 09:45 +0200, Markus Koschany wrote: > > > > Am 18.04.2016 um 08:45 schrieb Guido Günther: > > [...] > > > > > > > > > I'm all for it (although it's easy to say

Re: Supporting armel/armhf in wheezy-lts

2016-04-24 Thread Ben Hutchings
spending much time on architecture-specific issues in stable updates (other than x86). Ben. -- Ben Hutchings Larkinson's Law: All laws are basically false. signature.asc Description: This is a digitally signed message part

Re: working for wheezy-security until wheezy-lts starts

2016-04-24 Thread Ben Hutchings
On Wed, 2016-04-13 at 21:51 +1000, Brian May wrote: [...] > (dvswitch) [...] This is known to be broken with newer libav and has not been fixed upstream.  (I think I was able to make it build, but it then crashed at run-time.)  Definitely a candidate for removal. Ben. -- Ben Hutchi

Accepted linux-2.6 2.6.32-48squeeze20 (all source) into squeeze-lts

2016-02-28 Thread Ben Hutchings
-48squeeze20 Distribution: squeeze-lts Urgency: high Maintainer: Debian Kernel Team <debian-ker...@lists.debian.org> Changed-By: Ben Hutchings <b...@decadent.org.uk> Description: firmware-linux-free - Binary firmware for various drivers in the Linux kernel linux-base - Linux image base packag

Re: squeeze update of libssh2?

2016-02-23 Thread Ben Hutchings
eady fixed both libssh and libssh2 as I had advance notice under embargo. Ben. -- Ben Hutchings Any smoothly functioning technology is indistinguishable from a rigged demo. signature.asc Description: This is a digitally signed message part

[SECURITY] [DLA 426-1] libssh2 security update

2016-02-23 Thread Ben Hutchings
. For the oldstable (wheezy) and stable (jessie) distributions, this will be fixed soon. -- Ben Hutchings - Debian developer, member of Linux kernel and LTS teams signature.asc Description: This is a digitally signed message part

Re: Upgrading from Debian 6.0 LTS to 7

2016-02-20 Thread Ben Hutchings
, but it does not matter whether you do so before or after upgrading. Ben. > Any help would be much appreciated. > And a big thanks to LTS team for providing us LTS :) > -- Ben Hutchings Tomorrow will be cancelled due to lack of interest. signature.asc Description: This is a digitally signed message part

[SECURITY] [DLA 412-1] linux-2.6 security update

2016-02-06 Thread Ben Hutchings
and CVE-2016-0723 were fixed in linux version 3.16.7-ckt20-1+deb8u3 and the remaining problems will be fixed soon. -- Ben Hutchings - Debian developer, member of Linux kernel and LTS teams signature.asc Description: This is a digitally signed message part

Re: gajim 0.13.4-3+squeeze4 for testing

2016-02-04 Thread Ben Hutchings
some quilt files in the source which are > not applicable because gajim doesn't use quilt format. Ignore them, I > will fix this before uploading to squeeze-lts. I've been converting packages to 3.0 (quilt) where necessary, because it saves more time than I expect to waste in dealing with other patch system

Re: isc-dhcp-server in squeeze-lst broken after update

2016-01-18 Thread Ben Hutchings
On Mon, 2016-01-18 at 05:08 +, Mike Gabriel wrote: > Hi Ben, hi all, > > On  So 17 Jan 2016 23:42:19 CET, Ben Hutchings wrote: > > > On Sun, 2016-01-17 at 13:10 +0100, Olivier Dousse wrote: > > > Hi Mike, > > > > > > I have the exact same

Re: Re: isc-dhcp-server in squeeze-lst broken after update

2016-01-17 Thread Ben Hutchings
Additionally, the patch is *not* being applied isc-dhcp-server.  It is only applied when building isc-dhcp-server-ldap (see the commands for the build-stamp target).  It needs to be moved further up the patch series. Ben. -- Ben Hutchings Theory and practice are closer in

Security issues for jasper

2016-01-16 Thread Ben Hutchings
missing something? Ben. -- Ben Hutchings Theory and practice are closer in theory than in practice. - John Levine, moderator of comp.compilers signature.asc Description: This is a digitally signed message part

Re: squeeze update of openssh?

2016-01-15 Thread Ben Hutchings
> Would you like to take care of this yourself? [...] I believe Yves-Alexis Perez is handing this. Ben. -- Ben Hutchings The program is absolutely right; therefore, the computer must be wrong. signature.asc Description: This is a digitally signed message part

Re: squeeze update of openssh?

2016-01-15 Thread Ben Hutchings
On Fri, 2016-01-15 at 14:37 +0100, Yves-Alexis Perez wrote: > On ven., 2016-01-15 at 13:35 +0000, Ben Hutchings wrote: > > On Fri, 2016-01-15 at 11:46 +0100, Mike Gabriel wrote: > > > Hello dear maintainer(s), > > > > > > the Debian LTS team would l

Accepted inspircd 1.1.22+dfsg-4+squeeze3 (source) into squeeze-lts

2016-01-13 Thread Ben Hutchings
ain...@lists.alioth.debian.org> Changed-By: Ben Hutchings <b...@decadent.org.uk> Description: inspircd - Modular IRCd written in C++ inspircd-dbg - Modular IRCd written in C++ - debugging symbols Closes: 668253 Changes: inspircd (1.1.22+dfsg-4+squeeze3) squeeze-lts; urgency=medium . * No

[SECURITY] [DLA 384-1] inspircd security and regression update

2016-01-13 Thread Ben Hutchings
been fixed. -- Ben Hutchings - Debian developer, member of Linux kernel and LTS teams signature.asc Description: This is a digitally signed message part

<    1   2   3   4   >