Accepted libsndfile 1.0.25-9.1+deb7u3 (source amd64) into oldstable

2017-06-14 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Thu, 15 Jun 2017 08:11:03 +0800 Source: libsndfile Binary: libsndfile1-dev libsndfile1 sndfile-programs Architecture: source amd64 Version: 1.0.25-9.1+deb7u3 Distribution: wheezy-security Urgency: high Maintainer: Erik de Castro

[SECURITY] [DLA 985-1] libsndfile security update

2017-06-14 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libsndfile Version: 1.0.25-9.1+deb7u3 CVE ID : CVE-2017-6892 Debian Bug : #864704 It was discovered that there was a vulnerability in libsndfile, a library for reading/writing audio files. A specially-crafted

Wheezy update of libsndfile?

2017-06-14 Thread Chris Lamb
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of libsndfile: https://security-tracker.debian.org/tracker/source-package/libsndfile Would you like to take care of this yourself? If yes, please follow the workflow we

Re: smb4k CVE-2017-8849

2017-06-14 Thread Maximiliano Curia
¡Hola Salvatore! El 2017-06-13 a las 13:47 +0200, Salvatore Bonaccorso escribió: Thanks for analyzing the code for older versions. On Mon, Jun 12, 2017 at 11:52:00PM +0200, Markus Koschany wrote: I had a look at smb4k and CVE-2017-8849 and wanted to mark the package in Wheezy and Jessie as