February Report

2019-03-02 Thread Hugo Lefeuvre
Hi, Here is my LTS report for February. I was allocated 20 hours. I have spent all of them in the following tasks: * faad2: + work on patch for CVE-2018-20362. That was quite time consuming, the issue is tightly bound to some very specific parts of the AAC standard which is not exactl

Re: qemu CVE-2019-6501: not-affected in Jessie and Stretch?

2019-03-02 Thread Roberto C . Sánchez
On Wed, Feb 27, 2019 at 08:24:18AM +0100, Hugo Lefeuvre wrote: > Hi, > > It looks very much like the vulnerability was introduced in > a71c775b24ebc664129eb1d9b4c360590353efd5[0] which is not present prior > 2.12.50. > > I'd appreciate if a second pair of eyes could double check before I > update

Re: February Report

2019-03-02 Thread Hugo Lefeuvre
> Here is my LTS report for February. > > I was allocated 20 hours. I have spent all of them in the following > tasks: -> 19.5h, not 20. -- Hugo Lefeuvre (hle)|www.owl.eu.com RSA4096_ 360B 03B3 BF27 4F4D 7A3F D5E8 14AA 1EB8 A247 3DFD ed25519_ 37B2 6D38 0B25 B8A2 6B9F 3A6

Request for testing - symfony

2019-03-02 Thread Roberto C . Sánchez
I have prepared an update to symfony (version 2.3.21+dfsg-4+deb8u4) which is need of testing. I intend to upload in one week's time if I do not receive any reports of problems. Read on for details if you are in a position to help with testing these packages. I attempted to test the changes mysel