qemu status

2019-09-04 Thread Sylvain Beucler
Hi Gabriel, hi all :) We have a prepared QEMU update from 3 months ago that needs attention: https://packages.sunweavers.net/debian/pool/main/q/qemu/ It fixes: CVE-2017-9375 CVE-2019-12155 CVE-2017-15124 CVE-2016-5403 CVE-2016-5126 Since then we got: CVE-2019-14378 CVE-2019-13164 CVE-2019-12068

Re: Jessie update of ansible (minor security issues)?

2019-09-04 Thread Roberto C . Sánchez
On Sat, Aug 31, 2019 at 04:22:38PM +0200, Lee Garrett wrote: > > If you think it's a good thing I'm more than happy to help. I agree with > your assessment that all CVEs are of very low impact. There's a jessie > git branch you can make releases from which I can give you access to. If > you need a

Re: [Git][security-tracker-team/security-tracker][master] Add radare2 to dla-needed.txt with comments.

2019-09-04 Thread Moritz Mühlenhoff
On Thu, Aug 29, 2019 at 09:36:39AM +0200, Moritz Mühlenhoff wrote: > Adding the radare2 uploaders to CC. > > On Fri, Aug 16, 2019 at 11:23:05PM +0200, Markus Koschany wrote: > > >> + NOTE: 20190816: Affected by CVE-2019-14745. Vulnerable code is in > > >> + NOTE: libr/core/bin.c. Many no-dsa iss

Re: Jessie update of ansible (minor security issues)?

2019-09-04 Thread Holger Levsen
On Wed, Sep 04, 2019 at 02:07:39PM -0400, Roberto C. Sánchez wrote: > In any event, I have moved my work onto that branch and have already > some commits locally. Would you like for me to push my commits (one per > CVE) as I go so that you can look them over? Or would prefer that I > push all the