Re: [arch-general] JasPer vulnerabilities

2016-03-07 Thread Harrison Wells
On 07-Mar-2016 5:59 PM, "Levente Polyak" wrote: > > On 03/07/2016 01:04 PM, Harrison Wells wrote: > > Haven't reported in security list before. Should I just repost my previous > > message? > > It's a announcement only mailing list, discussions should g

Re: [arch-general] JasPer vulnerabilities

2016-03-07 Thread Harrison Wells
Haven't reported in security list before. Should I just repost my previous message? On 07-Mar-2016 5:28 PM, "LoneVVolf" wrote: > On 07-03-16 10:55, Harrison Wells wrote: > >> Is the package JasPer in extra repo vulnerable to CVE-2016-1577, >> CVE-2016-2089 and

[arch-general] JasPer vulnerabilities

2016-03-07 Thread Harrison Wells
Is the package JasPer in extra repo vulnerable to CVE-2016-1577, CVE-2016-2089 and CVE-2016-2116? I noticed that the version number of JasPer is same in Debian, Ubuntu and Arch, i.e. 1.900.1. Debian and Ubuntu seem to have updated/patched it, is Arch not vulnerable to it? With regards, Harrison

Re: [arch-general] Wget in Extra is out-of-date for more than two months

2016-02-25 Thread Harrison Wells
Still not clear what's the hold up. Will try to poke the maintainer on irc. On 25-Feb-2016 9:15 PM, "Eli Schwartz" wrote: > On 02/25/2016 08:48 AM, Harrison Wells wrote: > > Hello Archers, > > > > Is there any particular reason as to why Wget in the Extra rep

[arch-general] Wget in Extra is out-of-date for more than two months

2016-02-25 Thread Harrison Wells
Regards, Harrison Wells