Re: Long term improvement to Debian's security and LTS

2015-10-31 Thread Raphael Hertzog
Hi, On Fri, 30 Oct 2015, Guido Günther wrote: > Should we apply the attached patch to templates/lts-update-planned.txt > then? Yes, we should. > Salvatore suggested to move to a newer version of nss in all suites (and > keeping it that way). This plus adding some autpkgtests would be >

[SECURITY] [DLA 338-1] xscreensaver security update

2015-10-31 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: xscreensaver Version: 5.11-1+deb6u11 CVE ID : CVE-2015-8025 Debian Bug : 802914 xscreensaver, a screensaver daemon and frontend for X11 was vulnerable to crashing when hot-swapping monitors. For Debian 6

Accepted xscreensaver 5.11-1+deb6u11 (source amd64) into squeeze-lts

2015-10-31 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Sat, 31 Oct 2015 19:28:04 + Source: xscreensaver Binary: xscreensaver xscreensaver-data xscreensaver-data-extra xscreensaver-gl xscreensaver-gl-extra xscreensaver-screensaver-webcollage xscreensaver-screensaver-bsod

Re: data/CVE/list color

2015-10-31 Thread Guido Günther
Hi, On Sat, Aug 15, 2015 at 12:17:44PM +0200, Moritz Mühlenhoff wrote: > On Wed, Aug 12, 2015 at 06:23:25PM +0200, Guido Günther wrote: > > Hi, > > I wanted some color in debian/CVE/list so I hacked up some very simple > > highlighting > > for emacs: > > > > > >

Re: Long term improvement to Debian's security and LTS

2015-10-31 Thread Raphael Hertzog
On Fri, 30 Oct 2015, Moritz Muehlenhoff wrote: > > > - improving the security infrastructure > > That has certainly the best net positive from my point of view. >From my point of view too. But I'm not sure I would put the same emphasis as you on dak related work. I would possibly suggest to