Bug#876629: stretch-pu: package db5.3/5.3.28-12+deb9u1

2017-09-27 Thread Adam D. Barratt
Control: tags -1 + pending On Sun, 2017-09-24 at 18:27 +0200, Salvatore Bonaccorso wrote: > Hi Jonathan, > > On Sun, Sep 24, 2017 at 02:52:03PM +0100, Jonathan Wiltshire wrote: > > Control: tag -1 confirmed > > > > Hi, > > > > On Sun, Sep 24, 2017 at 09:52:06AM +0200, Salvatore Bonaccorso > >

Bug#876629: stretch-pu: package db5.3/5.3.28-12+deb9u1

2017-09-24 Thread Jonathan Wiltshire
On Sun, Sep 24, 2017 at 06:27:24PM +0200, Salvatore Bonaccorso wrote: > On Sun, Sep 24, 2017 at 02:52:03PM +0100, Jonathan Wiltshire wrote: > > > and have it > > > for a short time exposed as well via proposed-updates (once, and if > > > accepted). > > > > On that part I'm not so sure. If it's

Bug#876629: stretch-pu: package db5.3/5.3.28-12+deb9u1

2017-09-24 Thread Salvatore Bonaccorso
Hi Jonathan, On Sun, Sep 24, 2017 at 02:52:03PM +0100, Jonathan Wiltshire wrote: > Control: tag -1 confirmed > > Hi, > > On Sun, Sep 24, 2017 at 09:52:06AM +0200, Salvatore Bonaccorso wrote: > > db5.3 in stretch is affected by the CVE-2017-10140 ("Berkeley DB reads > > DB_CONFIG from cwd)",

Bug#876629: stretch-pu: package db5.3/5.3.28-12+deb9u1

2017-09-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed Hi, On Sun, Sep 24, 2017 at 09:52:06AM +0200, Salvatore Bonaccorso wrote: > db5.3 in stretch is affected by the CVE-2017-10140 ("Berkeley DB reads > DB_CONFIG from cwd)", #872436. The NMU to unstable back on end of > august has not raised any regression reports we would

Bug#876629: stretch-pu: package db5.3/5.3.28-12+deb9u1

2017-09-24 Thread Salvatore Bonaccorso
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Hi stable release managers, db5.3 in stretch is affected by the CVE-2017-10140 ("Berkeley DB reads DB_CONFIG from cwd)", #872436. The NMU to unstable back on end of august has not