Re: Debian LTS Security update of ruby-mail (advice needed)

2016-05-26 Thread Markus Koschany
Hi Ola, you have sent the security announcement for ruby-mail yesterday but the package hasn't been uploaded yet. One reason for that might be that it is the first upload to security-master thus ruby-mail must be built with -sa. You can follow all changes at https://lists.debian.org/debian-lts-ch

Re: Debian LTS Security update of ruby-mail (advice needed)

2016-05-26 Thread Ola Lundqvist
Hi Markus I realized (too late) that I had not checked the dak mail before I sent the mail. Sorry about that. Thanks for the note about sa option. I'll fix this as soon as possible. Do you think I need to step the revision or is a reupload good enough? / Ola Sent from a phone Den 26 maj 2016 0

Re: Debian LTS Security update of ruby-mail (advice needed)

2016-05-26 Thread Markus Koschany
Am 26.05.2016 um 09:21 schrieb Ola Lundqvist: > Hi Markus > > I realized (too late) that I had not checked the dak mail before I sent > the mail. Sorry about that. > > Thanks for the note about sa option. I'll fix this as soon as possible. > Do you think I need to step the revision or is a reupl

Re: Debian LTS Security update of ruby-mail (advice needed)

2016-05-26 Thread Ola Lundqvist
Hi Thanks. That explains why I did not get that mail. / Ola Sent from a phone Den 26 maj 2016 09:28 skrev "Markus Koschany" : > Am 26.05.2016 um 09:21 schrieb Ola Lundqvist: > > Hi Markus > > > > I realized (too late) that I had not checked the dak mail before I sent > > the mail. Sorry about

Re: [Pkg-samba-maint] Bug#821811: samba: badlock patch breaks trust relationship

2016-05-26 Thread Santiago Ruano Rincón
El 23/05/16 a las 22:28, Andrew Bartlett escribió: > On Wed, 2016-05-18 at 15:47 -0400, Antoine Beaupré wrote: > > On 2016-04-29 08:55:43, Santiago Ruano Rincón wrote: > > > Dear Samba maintainers, > > > > > > Any updates about this bug? > > > > > > LTS Team, anyone could help to handle it? > > >

Re: [php-maint] php5-curl

2016-05-26 Thread Ondřej Surý
Dear Baxtiyor, the Debian Wheezy is now supported by Debian LTS team that can be contacted via: debian-lts@lists.debian.org However you didn't specify any package version, so it's unlikely that anybody can help you if you don't provide more details first like the version of: php5-common php5-cli

How to handle the case with no CVE

2016-05-26 Thread Ola Lundqvist
Hi I have now fixed ruby-mail and the problem described there did not have a CVE identifier. See here: https://security-tracker.debian.org/tracker/source-package/ruby-mail Instead it has a TEMP-000-8B2928 identifier. How do I mark that one as fixed? I could not add TEMP-... to to gen-DLA com

Re: How to handle the case with no CVE

2016-05-26 Thread Salvatore Bonaccorso
Hi, On Thu, May 26, 2016 at 12:11:42PM +0200, Ola Lundqvist wrote: > Hi > > I have now fixed ruby-mail and the problem described there did not have a > CVE identifier. > See here: > https://security-tracker.debian.org/tracker/source-package/ruby-mail > Instead it has a TEMP-000-8B2928 identif

Re: How to handle the case with no CVE

2016-05-26 Thread Ola Lundqvist
Hi Salvatore Thanks for quick answer. Yes I have seen that and uploaded to the archive. I guess it has not been processed yet. A CVE request was made half a year ago, but none assigned that I could find. Regarding the addition if a line to data/CVE/list. Shall I add it to a dummy id because the

Re: Debian LTS Security update of ruby-mail (advice needed)

2016-05-26 Thread Ola Lundqvist
Hi I have now fixed this problem. Thanks again. // Ola On Thu, May 26, 2016 at 9:28 AM, Markus Koschany wrote: > Am 26.05.2016 um 09:21 schrieb Ola Lundqvist: > > Hi Markus > > > > I realized (too late) that I had not checked the dak mail before I sent > > the mail. Sorry about that. > > > >

Re: How to handle the case with no CVE

2016-05-26 Thread Salvatore Bonaccorso
Hi Ola, On Thu, May 26, 2016 at 12:27:32PM +0200, Ola Lundqvist wrote: > Hi Salvatore > > Thanks for quick answer. > > Yes I have seen that and uploaded to the archive. I guess it has not been > processed yet. > > A CVE request was made half a year ago, but none assigned that I could find. Yes

Re: How to handle the case with no CVE

2016-05-26 Thread Salvatore Bonaccorso
Hi Ola, On Thu, May 26, 2016 at 12:27:32PM +0200, Ola Lundqvist wrote: > Hi Salvatore > > Thanks for quick answer. > > Yes I have seen that and uploaded to the archive. I guess it has not been > processed yet. https://lists.debian.org/debian-lts-changes/2016/05/msg00063.html Regards, Salvatore

Re: How to handle the case with no CVE

2016-05-26 Thread Ola Lundqvist
Thanks a lot! // Ola On Thu, May 26, 2016 at 12:32 PM, Salvatore Bonaccorso wrote: > Hi Ola, > > On Thu, May 26, 2016 at 12:27:32PM +0200, Ola Lundqvist wrote: > > Hi Salvatore > > > > Thanks for quick answer. > > > > Yes I have seen that and uploaded to the archive. I guess it has not been > >

About the security issues affecting ruby-jquery-rails in Wheezy

2016-05-26 Thread Ola Lundqvist
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello dear maintainer(s), the Debian LTS team recently reviewed the security issue(s) affecting your package in Wheezy: https://security-tracker.debian.org/tracker/CVE-2015-1840 We decided that we would not prepare a wheezy security update (usually

About the security issues affecting ruby-rest-client in Wheezy

2016-05-26 Thread Ola Lundqvist
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello dear maintainer(s), The Debian LTS team recently reviewed the security issue(s) affecting your package in Wheezy: https://security-tracker.debian.org/tracker/CVE-2015-1820 We decided that we would not prepare a wheezy security update (usually

Re: Iceweasel 45 for Wheezy-LTS

2016-05-26 Thread Mike Hommey
On Sun, May 22, 2016 at 07:34:29PM +0200, Guido Günther wrote: > Hi Mike, > I'm currently looking into building icedove 45 for Wheezy-LTS. I wonder > if I should do the same for Iceweasel or if you intend to keep > maintaining Iceweasel in LTS yourself? I don't know yet. The last message in bug 81

Re: Iceweasel 45 for Wheezy-LTS

2016-05-26 Thread Moritz Muehlenhoff
On Thu, May 26, 2016 at 10:29:22PM +0900, Mike Hommey wrote: > On Sun, May 22, 2016 at 07:34:29PM +0200, Guido Günther wrote: > > Hi Mike, > > I'm currently looking into building icedove 45 for Wheezy-LTS. I wonder > > if I should do the same for Iceweasel or if you intend to keep > > maintaining I

Debian LTS Security update of ruby-activerecord-3.2

2016-05-26 Thread Ola Lundqvist
Hi ruby-activerecord-3.2 maintainer(s) and Debian LTS team This is my third package contribution to Debian LTS. I'm doing this as a training exercise and this is why the maintainer have not been asked to this for me. I have prepared an update of the ruby-activerecord-3.2 package with a fix for ht

About the security issues affecting dhcpcd5 in Wheezy

2016-05-26 Thread Ola Lundqvist
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello dear maintainer(s), the Debian LTS team recently reviewed the security issue(s) affecting your package in Wheezy: https://security-tracker.debian.org/tracker/CVE-2016-1504 https://security-tracker.debian.org/tracker/CVE-2016-1503 We decided t