April report

2017-04-19 Thread Brian May
Brian May writes: This month I had 10 hours and I spent my 10 hours on the following tasks: * XBMC CVE-2017-5982. This is slow going due to time taken to build different versions. I found that *all* versions of xmbc/kodi are vulnerable, and (contrary to some websites) there is no upstream fi

Re: April report

2017-04-19 Thread Antoine Beaupré
On 2017-04-19 19:05:36, Brian May wrote: [...] > As I have run out of hours this month, if anybody else wants to take > over either of these, please let me know and I will provide more > details. I'd take a look at the XBMC thing... a. -- L'adversaire d'une vraie liberté est un désir excessif

Re: April report

2017-04-19 Thread Markus Koschany
Am 19.04.2017 um 11:05 schrieb Brian May: > Brian May writes: [...] > * Heimdal CVE-2017-6594. Prepared initial patch for Wheezy/Stretch > release before it was publicly announced, although found it was > missing a hunk. This has been corrected in the official release. > > The fix applies c

Wheezy update of gnutls26?

2017-04-19 Thread Ola Lundqvist
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of gnutls26: https://security-tracker.debian.org/tracker/CVE-2017-5337 https://security-tracker.debian.org/tracker/CVE-2017-5336 https://security-tracker.debian.org/tracker/

Re: April report

2017-04-19 Thread Brian May
Antoine Beaupré writes: > On 2017-04-19 19:05:36, Brian May wrote: > > [...] > >> As I have run out of hours this month, if anybody else wants to take >> over either of these, please let me know and I will provide more >> details. > > I'd take a look at the XBMC thing... The webserver is in xbmc

Re: April report

2017-04-19 Thread Brian May
Markus Koschany writes: > Since you are also the maintainer of Heimdal, do you intend to upload > the fix to Wheezy this month? I just got a respone from the security team on this. They feel it isn't a serious issue, because not many people use Kerberos in multi-realm mode. So they have suggeste

Re: [SECURITY] [DLA 895-1] openoffice.org-dictionaries update

2017-04-19 Thread Pascal-liste
Hello, Le 14/04/2017 à 21:23, Guido Günther a écrit : Package: openoffice.org-dictionaries Version: 3.3.0~rc10-4+deb7u1 Debian Bug : #646693 The dictionaries provided by this package had an unversioned conflict against the thunderbird package (which so far was not part of wh

Re: [SECURITY] [DLA 895-1] openoffice.org-dictionaries update

2017-04-19 Thread Guido Günther
Hi, On Thu, Apr 20, 2017 at 12:14:10AM +0200, Pascal-liste wrote: > Hello, > > Le 14/04/2017 à 21:23, Guido Günther a écrit : > > Package: openoffice.org-dictionaries > > Version: 3.3.0~rc10-4+deb7u1 > > Debian Bug : #646693 > > > > The dictionaries provided by this package ha