LTS report for September 2020

2020-10-06 Thread Adrian Bunk
Hours worked: 14 hours DLAs released: DLA-2376-1 qtbase-opensource-src CVE-2018-19872 CVE-2020-17507 DLA-2377-1 qt4-x11 CVE-2018-15518 CVE-2018-19869 CVE-2018-19870 CVE-2018-19871 CVE-2018-19872 CVE-2018-19873 CVE-2020-17507 DLA-2388-1 nss CVE-2018-12404 CVE-2018-18508 CVE-2019-11719 CVE-2019-1

About sympa

2020-10-06 Thread Utkarsh Gupta
Hi Sylvain, I see you recently claimed sympa in dla-needed.txt. Please let me tell you that the upload is already ready and tested on my end. Just waiting on having some internal confirmation to release the upload. So I guess it's better for to leave it right now, I'll release the upload this mon

Re: About sympa

2020-10-06 Thread Sylvain Beucler
Hi, On 06/10/2020 20:42, Utkarsh Gupta wrote: > I see you recently claimed sympa in dla-needed.txt. > Please let me tell you that the upload is already ready and tested on my end. > > Just waiting on having some internal confirmation to release the upload. > So I guess it's better for to leave it

Re: golang-go.crypto / CVE-2019-11841

2020-10-06 Thread Brian May
Utkarsh Gupta writes: > Ah, great. It'd nice to include this then! :) Done. See attached patch. I had to apply it manually, because patch was misapplying one of the hunks in the wrong place. There were several hunks that apply to SKEd25519 public key stuff I skipped also because this version doe

Re: golang-go.crypto / CVE-2019-11841

2020-10-06 Thread Utkarsh Gupta
Hi Brian, On Wed, Oct 7, 2020 at 3:13 AM Brian May wrote: > Done. See attached patch. I had to apply it manually, because patch was > misapplying one of the hunks in the wrong place. There were several > hunks that apply to SKEd25519 public key stuff I skipped also because > this version does not

Re: Bug#971560: libsane-common 1.0.25-4.1+deb9u1 Stretch security update missing lots of files

2020-10-06 Thread Ivan Baldo
Hello. "¡Lo prometido es deuda!" as we say in Uruguay (what is promised is a debt). Tested your packages and now I can see correctly all the scanners, local and networked ones! So everything looks good to push those to Debian Stretch. Thanks a lot for doing all this! Greetings from another Allegro