LTS/ELTS Report for September 2019

2019-11-01 Thread Roberto C . Sánchez
For October I spent 8 hours on the following LTS tasks:

- libreoffice: multiple issues, including CVE-2019-9848 CVE-2019-9849
  CVE-2019-9850 CVE-2019-9851 CVE-2019-9852 CVE-2019-9853 CVE-2019-9854
- openconnect: CVE-2019-16239
- ampache: CVE-2019-12385, CVE-2019-12386 triage and worked with
  upstream to obtain specific patches (the fixes were made in a very
  large single commit toward a new upstream release)

As a result of the few ELTS tasks available, I did not spend any hours
on ELTS tasks.

Regards,

-Roberto

-- 
Roberto C. Sánchez



LTS/ELTS Report for September 2019

2019-10-01 Thread Roberto C . Sánchez
For September I spent 16 hours on the following LTS tasks:

- ansible: multiple issues, including the recently reported
  CVE-2019-10156 and several previously no-dsa/postponed fixes
- mongodb: CVE-2019-2386, triaged and found to not apply
- libcommons-compress-java: CVE-2019-12402
- php5: fix for #805222, which prevented building PHP extensions
- php-pecl-http: CVE-2016-7398
- python3.4, python2.7: CVE-2019-16506

I also spent 8 hours on the following ELTS tasks:

- python2.7, python2.6: CVE-2019-16506 and numerous previously
  no-dsa/postponed fixes

Regards,

-Roberto

-- 
Roberto C. Sánchez