Slides and video of my Debian LTS talk

2015-04-14 Thread Raphael Hertzog
Hello everybody, I just wanted to let you know that the slides of the LTS talk I gave on Sunday are available: https://wiki.debian.org/DebianEvents/fr/2015/Minidebconf?action=AttachFile&do=get&target=debian-lts-presentation.pdf You can also watch the full presentation here: http://meetings-archiv

Re: squeeze update of shibboleth-sp2?

2015-04-14 Thread Matthew Vernon
On 14/04/15 07:57, Raphael Hertzog wrote: > On Mon, 13 Apr 2015, Ferenc Wagner wrote: >> Anyway, I pushed the backported fix to the squeeze branch of >> http://anonscm.debian.org/cgit/pkg-shibboleth/shibboleth-sp2.git. You >> can find the corresponding source package at http://apt.niif.hu/lts/ >>

Re: How to deal with wireshark CVE affecting Squeeze

2015-04-14 Thread Bálint Réczey
Hi, 2015-04-12 20:36 GMT+02:00 Raphael Hertzog : > On Sun, 12 Apr 2015, Bálint Réczey wrote: >> I have prepared the attached patch implementing b.). If no one opposes >> I will upload it on Tuesday. >> The change is not backwards-compatible in a sense that custom software >> may break, but those >

Re: Draft for a LTS press release

2015-04-14 Thread Neil McGovern
On Mon, Apr 13, 2015 at 09:18:47PM +0200, Raphael Hertzog wrote: > > If the former, then we should definitely change quite a bit of the > > wording in paragraph 4 to soften it. > > > > If the latter - would a d-d-a posting do instead? > > I'm afraid that a d-d-a posting is not very useful. People

Re: Draft for a LTS press release

2015-04-14 Thread Raphael Hertzog
Hi, On Tue, 14 Apr 2015, Neil McGovern wrote: > Diff attached! There's not a particular problem, I was trying to work > out the audience. We can me more blunt with developers than in an > official announcement from the project. Thanks, merged into https://titanpad.com/x9keVJLExl The only part th

Re: How to deal with wireshark CVE affecting Squeeze

2015-04-14 Thread Holger Levsen
Hi Balint, On Dienstag, 14. April 2015, Bálint Réczey wrote: > I have prepared the DLA and uploaded the fixed package but it ended up in > NEW. Dear FTP Masters, please accept it. what distribution did you use in debian/changelog? cheers, Holger signature.asc Description: This is a d

Re: How to deal with wireshark CVE affecting Squeeze

2015-04-14 Thread Bálint Réczey
2015-04-14 14:47 GMT+02:00 Holger Levsen : > Hi Balint, > > On Dienstag, 14. April 2015, Bálint Réczey wrote: >> I have prepared the DLA and uploaded the fixed package but it ended up in >> NEW. Dear FTP Masters, please accept it. > > what distribution did you use in debian/changelog? squeeze-lts,

Re: How to deal with wireshark CVE affecting Squeeze

2015-04-14 Thread Holger Levsen
On Dienstag, 14. April 2015, Bálint Réczey wrote: > squeeze-lts, both in *.changes and *.changelog. > The binary package names changed quite a lot so I think entering NEW > was reasonable. ah. makes sense :) signature.asc Description: This is a digitally signed message part.

Re: Draft for a LTS press release

2015-04-14 Thread Neil McGovern
On Tue, Apr 14, 2015 at 02:36:44PM +0200, Raphael Hertzog wrote: > On Tue, 14 Apr 2015, Neil McGovern wrote: > > Diff attached! There's not a particular problem, I was trying to work > > out the audience. We can me more blunt with developers than in an > > official announcement from the project. >

squeeze update of ppp?

2015-04-14 Thread Raphael Hertzog
Hello Marco & Emanuele, the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of ppp: https://security-tracker.debian.org/tracker/source-package/ppp Would you like to take care of this yourself? We are still understaffed so any help is always hi

Re: squeeze update of ppp?

2015-04-14 Thread Marco d'Itri
On Apr 14, Raphael Hertzog wrote: > Would you like to take care of this yourself? We are still understaffed so No, I am not sure if we will fix it for stable either. It is not really such a big deal, so I am not concerned. -- ciao, Marco pgpWix2Njndnj.pgp Description: PGP signature

Re: [debian-lts] file package

2015-04-14 Thread Raphael Hertzog
Hello Christoph, On Tue, 17 Feb 2015, Raphael Hertzog wrote: > > I indeed forgot about that this time. So go ahead. > > Nguyent already replied to you[1] to inform you that you can go ahead > and the he discarded his work. I updated dla-needed.txt to put your name. You're still listed as taking

Re: [debian-lts] libvncserver package

2015-04-14 Thread Raphael Hertzog
Hello Nguyen, Sorry for the delay, this update fell through the cracks. Don't hesitate to ping us when we don't respond in a timely fashion. On Mon, 19 Jan 2015, Nguyen Cong wrote: > I would like to send debdiff of libvncserver package for reviewing. > > Could any one please review it and give m

Draft for a LTS press release

2015-04-14 Thread Neil McGovern
Hi all, I've committed jessie-lts-help.wml to publicity/announcements/en/drafts [0] - can we have reviews over the next day or so, and then the translators can get started? Let's go for the following dates: Now -> Thurs: Amendments Fri -> Mon: Translations Mon evening (UTC): Publish Neil [0] htt

Bug#782615: nmu: multiple bin-NMU in squeeze-lts for CVE-2013-7439

2015-04-14 Thread Raphael Hertzog
Package: release.debian.org User: release.debian@packages.debian.org Usertags: binnmu Severity: normal Hello, I'm wondering whether bin-NMU are possible in squeeze-lts for packages which are not in squeeze-lts but in squeeze only. My question is related to the handling of https://security-tr

Re: [debian-lts] libvncserver package

2015-04-14 Thread Nguyen Cong
Hi Raphael, Thank you very much for uploading my work. Did you base your work on the patches that have been released in the wheezy update? In fact, most of my work is based on information from this: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=762745 It's not that I'm trying to take the f