Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-12 Thread Mike Gabriel
Hi Moritz, On Wednesday, 12 December 2018, Moritz Mühlenhoff wrote: > On Wed, Dec 12, 2018 at 03:46:10PM +, Mike Gabriel wrote: > > Hi Moritz, > > > > On Di 11 Dez 2018 22:15:33 CET, Moritz Mühlenhoff wrote: > > > > > On Tue, Dec 11, 2018 at 04:42:17PM +, Mike Gabriel wrote: > > > > Fro

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-12 Thread Moritz Mühlenhoff
On Wed, Dec 12, 2018 at 03:46:10PM +, Mike Gabriel wrote: > Hi Moritz, > > On Di 11 Dez 2018 22:15:33 CET, Moritz Mühlenhoff wrote: > > > On Tue, Dec 11, 2018 at 04:42:17PM +, Mike Gabriel wrote: > > > From my understanding the potential remote code executions that are > > > mentioned in

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-12 Thread Mike Gabriel
Hi Moritz, On Di 11 Dez 2018 22:15:33 CET, Moritz Mühlenhoff wrote: On Tue, Dec 11, 2018 at 04:42:17PM +, Mike Gabriel wrote: From my understanding the potential remote code executions that are mentioned in the CVE descriptions are triggered by a malign server and the code executions then

Re: poppler: CVE-2018-16646 denial-of-service via crafted file

2018-12-12 Thread Mike Gabriel
Hi Moritz, On Mi 12 Dez 2018 11:46:32 CET, Moritz Mühlenhoff wrote: On Thu, Nov 08, 2018 at 10:51:37AM +, Mike Gabriel wrote: Hi Moritz, On Di 06 Nov 2018 17:14:35 CET, Moritz Mühlenhoff wrote: > On Fri, Sep 28, 2018 at 08:32:25PM +0200, Markus Koschany wrote: > > Package: poppler > >

Re: Possible patch-backport problem for libphp-phpmailer (DLA-1591-1)

2018-12-12 Thread Abhijith PA
Hi. On Tuesday 11 December 2018 12:36 PM, Salvatore Bonaccorso wrote: > Hi > > While preparing an update for libphp-phpmailer I noticed in the > patch/diff for DLA-1591-1 for libphp-phpmailer the following: > > +--- libphp-phpmailer-5.2.9+dfsg.orig/class.phpmailer.php > libphp-phpmailer-5.2

(E)LTS report for November

2018-12-12 Thread Emilio Pozuelo Monfort
Hi, In November, I spent 38h in Debian LTS, on the following tasks: Finished the rustc and cargo bootstrap, which allowed to update firefox-esr and thunderbird. There was a problem with rustc on i386, which I investigated and finally fixed, allowing firefox-esr/thunderbird to build there too. The

Re: poppler: CVE-2018-16646 denial-of-service via crafted file

2018-12-12 Thread Moritz Mühlenhoff
On Thu, Nov 08, 2018 at 10:51:37AM +, Mike Gabriel wrote: > Hi Moritz, > > On Di 06 Nov 2018 17:14:35 CET, Moritz Mühlenhoff wrote: > > > On Fri, Sep 28, 2018 at 08:32:25PM +0200, Markus Koschany wrote: > > > Package: poppler > > > X-Debbugs-CC: t...@security.debian.org > > > Severity: impor