Wheezy update of libpdfbox-java?

2016-05-31 Thread Ben Hutchings
Hello dear maintainer(s),

the Debian LTS team would like to fix the security issues which are
currently open in the Wheezy version of libpdfbox-java:
https://security-tracker.debian.org/tracker/CVE-2016-2175

Would you like to take care of this yourself?

If yes, please follow the workflow we have defined here:
https://wiki.debian.org/LTS/Development

If that workflow is a burden to you, feel free to just prepare an
updated source package and send it to debian-lts@lists.debian.org
(via a debdiff, or with an URL pointing to the source package,
or even with a pointer to your packaging repository), and the members
of the LTS team will take care of the rest. Indicate clearly whether you
have tested the updated package or not.

If you don't want to take care of this update, it's not a problem, we
will do our best with your package. Just let us know whether you would
like to review and/or test the updated package before it gets released.

Thank you very much.

Ben Hutchings,
  on behalf of the Debian LTS team.

PS: A member of the LTS team might start working on this update at
any point in time. You can verify whether someone is registered
on this update in this file:
https://anonscm.debian.org/viewvc/secure-testing/data/dla-needed.txt?view=markup

-- 
Ben Hutchings - Debian developer, member of kernel, installer and LTS teams

signature.asc
Description: This is a digitally signed message part


Re: Wheezy update of libpdfbox-java?

2016-06-01 Thread Emmanuel Bourg
Le 1/06/2016 à 03:01, Ben Hutchings a écrit :

> the Debian LTS team would like to fix the security issues which are
> currently open in the Wheezy version of libpdfbox-java:
> https://security-tracker.debian.org/tracker/CVE-2016-2175
> 
> Would you like to take care of this yourself?

Hi Ben,

Thank you for the notice. I uploaded a fix to unstable, I'll a wait a
bit before uploading an update for jessie and wheezy because the fix may
break the reverse dependencies (a similar issue in libxstream-java broke
a feature of jmeter).

Emmanuel Bourg