Re: Wheezy update of leptonlib?

2018-02-22 Thread Jeff Breidenbach
There a multiple email threads about leptonlib. I'll be as responsive as I can to them, but LTS team should take the lead.

Re: upload leptonlib

2018-02-22 Thread Jeff Breidenbach
These binaries were removed in #830660. >$ strings /usr/bin/printsplitimage | grep ^/tmp/ >/tmp/split >$ strings /usr/bin/splitimage2pdf | grep ^/tmp/ >/tmp/junk_split_image.ps prune_unsafe_binaries.diff.gz Description: GNU Zip compressed data

Re: upload leptonlib

2018-02-22 Thread Jeff Breidenbach
The remaining hardcoded /tmp filenames are believed to be in test and debug code paths.

Re: Wheezy update of irssi?

2018-02-22 Thread Chris Lamb
Hey Rhonda, I've gone ahead and uploaded 0.8.15-5+deb7u5 and announced DLA 1289-1. > It still would be nice to get some git patchsets for your uploads so I > can apply them to the repository Of course! Attached, including the "missing" changes for 0.8.15-5+deb7u2, 0.8.15-5+deb7u3 &

[SECURITY] [DLA 1289-1] irssi security update

2018-02-22 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: irssi Version: 0.8.15-5+deb7u5 CVE IDs: CVE-2018-7050 CVE-2018-7051 CVE-2018-7052 Debian Bugs: #890676, #890677, #890678 It was discovered that there where a number of vulnerabilities in irssi, the terminal

Re: upload leptonlib

2018-02-22 Thread Salvatore Bonaccorso
Hi Ben, On Thu, Feb 22, 2018 at 05:38:16PM +0100, Ben Hutchings wrote: > On Thu, 2018-02-22 at 07:26 +0100, Salvatore Bonaccorso wrote: > > Hi Ben, > > > > On Sat, Feb 17, 2018 at 09:28:19PM +, Ben Hutchings wrote: > > > On Fri, 2018-02-16 at 14:36 -0500, Antoine Beaupré wrote: > > > > On

Re: upload leptonlib

2018-02-22 Thread Ben Hutchings
On Thu, 2018-02-22 at 07:26 +0100, Salvatore Bonaccorso wrote: > Hi Ben, > > On Sat, Feb 17, 2018 at 09:28:19PM +, Ben Hutchings wrote: > > On Fri, 2018-02-16 at 14:36 -0500, Antoine Beaupré wrote: > > > On 2018-02-15 21:34:48, Ben Hutchings wrote: > > > > On Wed, 2018-02-14 at 22:23 -0500,

[SECURITY] [DLA 1288-1] cups security update

2018-02-22 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: cups Version: 1.5.3-5+deb7u7 CVE ID : CVE-2017-18190 It was discovered that there was an issue in the CUPS printer framework where remote attackers could execute arbitrary commands by sending POST requests to the

Accepted cups 1.5.3-5+deb7u7 (source all amd64) into oldoldstable

2018-02-22 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Thu, 22 Feb 2018 14:17:48 + Source: cups Binary: libcups2 libcupsimage2 libcupscgi1 libcupsdriver1 libcupsmime1 libcupsppdc1 cups cups-client libcups2-dev libcupsimage2-dev libcupscgi1-dev libcupsdriver1-dev libcupsmime1-dev

Re: Wheezy update of irssi?

2018-02-22 Thread Rhonda D'Vine
* Antoine Beaupré [2018-02-16 21:01:48 CET]: > On 2017-12-22 13:53:46, Rhonda D'Vine wrote: > > * Emilio Pozuelo Monfort [2017-12-19 20:04:57 CET]: > > Given that you would be paid to do the update and me not there is > > little sense for me to do it,

Re: Wheezy update of irssi?

2018-02-22 Thread Chris Lamb
Hey Rhonda, I trust this finds you well? :) > I think people in the LTS team would be happy either way Unless you have Strong Opinions, I'm going go ahead and upload to LTS tomorrow to fix CVE-2018-7050, CVE-2018-7051 & CVE-2018-7052. Naturally do let me know if I should hold off for

Re: Extended Long Term Support for Wheezy

2018-02-22 Thread Raphael Hertzog
Hello, On Tue, 20 Feb 2018, Vincent Bernat wrote: > My bad. I suggest replacing "it would not be possible to get extended > wheezy support" by "it would not be possible to sponsor extended wheezy > support". Done. Cheers, -- Raphaël Hertzog ◈ Debian Developer Support Debian LTS: