Re: Call for tests: Making OpenJDK 7 the default in Wheezy LTS

2016-04-25 Thread Rene Engelhard
Hi, On Wed, Apr 20, 2016 at 06:22:51PM +0200, Markus Koschany wrote: > I would like to ask everyone who uses Java in server or desktop > environments to test their applications with OpenJDK 7 and to prepare > for the switch. This can be achieved by installing either openjdk-7-jre > or openjdk-7-jr

Re: Call for tests: Making OpenJDK 7 the default in Wheezy LTS

2016-04-25 Thread Rene Engelhard
Hi, On Mon, Apr 25, 2016 at 12:17:52PM +0200, Markus Koschany wrote: > we are mainly concerned about runtime issues with OpenJDK 7. Libreoffice > declares dependencies on default-jre | openjdk-7-jre, so I believe it > should be fine. I am aware of build failures with OpenJDK 7 and I think > that c

Re: Call for tests: Making OpenJDK 7 the default in Wheezy LTS

2016-04-25 Thread Rene Engelhard
Hi, On Mon, Apr 25, 2016 at 12:34:53PM +0200, Markus Koschany wrote: > Am 25.04.2016 um 12:23 schrieb Rene Engelhard: > > On Mon, Apr 25, 2016 at 12:17:52PM +0200, Markus Koschany wrote: > >> we are mainly concerned about runtime issues with OpenJDK 7. Libreoffice > >&g

Re: Wheezy update of libreoffice?

2016-07-28 Thread Rene Engelhard
Hi, On Wed, Jul 27, 2016 at 10:03:13AM +0200, Balint Reczey wrote: > the Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of libreoffice: > https://security-tracker.debian.org/tracker/CVE-2016-4324 > > Would you like to take care of this yours

Re: Wheezy update of libreoffice?

2016-07-28 Thread Rene Engelhard
Hi again, On Wed, Jul 27, 2016 at 10:03:13AM +0200, Balint Reczey wrote: > If that workflow is a burden to you, feel free to just prepare an > updated source package and send it to debian-lts@lists.debian.org > (via a debdiff, or with an URL pointing to the source package, > or even with a pointer

Re: Wheezy update of libreoffice?

2016-07-28 Thread Rene Engelhard
Hi, On Thu, Jul 28, 2016 at 07:12:16PM +0200, Bálint Réczey wrote: > Thank you for preparing the patch. > I'm building it right now and would like to test it if you have not done so > yet. > After it is tested feel free to upload it. Then it's best you mergechanges and upload after testing, I on

Wheezy update of libreoffice #2 (CVE-2016-1513)

2016-08-03 Thread Rene Engelhard
[ CC'ing team@security so that they know nothing supported is affected by it. ] Hi, apparently Apache knew it since October 2015, tested with "current" LibreOffices but they said they didn't test with old, so didn't inform LO *at all* until this came up last Thursday again confirming that old LOs

Re: Wheezy update of libreoffice #2 (CVE-2016-1513)

2016-08-04 Thread Rene Engelhard
Hi, On Thu, Aug 04, 2016 at 06:43:36AM +0200, Rene Engelhard wrote: > A (untested, except that the patch applies) source package is - as last time - > available on http://people.debian.org/~rene/libreoffice/wheezy I noticed Balint did some additional changes to deb7u7 (build-depends on

Re: Wheezy update of libreoffice #2 (CVE-2016-1513)

2016-08-04 Thread Rene Engelhard
Hi, On Thu, Aug 04, 2016 at 09:12:04AM +0200, Rene Engelhard wrote: > I noticed Balint did some additional changes to deb7u7 (build-depends > on fixed graphite2 - thanks for that), so this needs > either be merged into my deb7u8 or I can redo it this evening... now done. Regards, Rene

Re: Wheezy update of libreoffice #2 (CVE-2016-1513)

2016-08-06 Thread Rene Engelhard
Hi, On Fri, Aug 05, 2016 at 07:00:11PM +0200, Bálint Réczey wrote: > 2016-08-04 19:34 GMT+02:00 Rene Engelhard : > > Hi, > > > > On Thu, Aug 04, 2016 at 09:12:04AM +0200, Rene Engelhard wrote: > >> I noticed Balint did some additional changes to deb7u7 (build-d

Re: [SECURITY] [DSA 3792-1] libreoffice security update

2017-02-23 Thread Rene Engelhard
Hi, On Thu, Feb 23, 2017 at 11:13:34PM +0100, Moritz Muehlenhoff wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > - - > Debian Security Advisory DSA-3792-1 secur...@debian.org > https://www.deb

Re: [SECURITY] [DSA 3792-1] libreoffice security update

2017-02-24 Thread Rene Engelhard
Hi, On Fri, Feb 24, 2017 at 09:01:52AM +0100, Bálint Réczey wrote: > > I have also prepared it for wheezy-lts. Should build (my build is > > still running), basically just took the patch from Ubuntu (in contrast to So far for this.. [ build CXX ] sd/source/core/drawdoc R=/home/rene/Debian/Pakete

Re: [SECURITY] [DSA 3792-1] libreoffice security update

2017-02-25 Thread Rene Engelhard
Hi, On Fri, Feb 24, 2017 at 12:38:29PM +0100, Rene Engelhard wrote: > [ build CXX ] sd/source/ui/docshell/docshel4 > /home/rene/Debian/Pakete/LibreOffice/libreoffice/libreoffice-3.5.4+dfsg2/sd/source/core/drawdoc.cxx: > In member function 'void SdDrawDocument::UpdateAllLinks()&

Re: [SECURITY] [DSA 3792-1] libreoffice security update

2017-03-01 Thread Rene Engelhard
Hi, On Tue, Feb 28, 2017 at 01:51:08AM +0100, Bálint Réczey wrote: > Do you have a PoC for testing? > I tried triggering the issue on Wheezy without any luck so far. Forwarded you the original mail from September in private mail. Regards, Rene

Re: Problem with LibreOffice Calc

2017-05-05 Thread Rene Engelhard
Hi, On Fri, May 05, 2017 at 01:01:38PM +1000, Allan Hughson wrote: >I upgraded to version: 1:3.5.4+dfsg2-0+deb7u9 yesterday and noticed the Yesterday? https://lists.debian.org/debian-lts-announce/2017/04/msg00029.html. April 23. Not upgrading for security issues in two weeks? >charts in

Re: Wheezy update of graphite2?

2017-06-20 Thread Rene Engelhard
Hi, On Tue, Jun 20, 2017 at 12:16:17PM +0200, Raphael Hertzog wrote: > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of graphite2: > https://security-tracker.debian.org/tracker/source-package/graphite2 > > Last time we had issues, it lo

Re: Wheezy update of graphite2?

2017-06-20 Thread Rene Engelhard
Hi, On Tue, Jun 20, 2017 at 12:56:03PM +0200, Rene Engelhard wrote: > On Tue, Jun 20, 2017 at 12:16:17PM +0200, Raphael Hertzog wrote: > > The Debian LTS team would like to fix the security issues which are > > currently open in the Wheezy version of graphite2: >

Re: Bug#892590: Review graphite2

2018-03-19 Thread Rene Engelhard
On Sun, Mar 18, 2018 at 11:39:57AM +0530, Abhijith PA wrote: > I prepared LTS security update for graphite2[1]. Debdiff is attached. > All tests ran successfully. Please review. Why would we need one given for jessie and stretch it is clearly marked as no-DSA? https://security-tracker.debian.org/

Re: Bug#892590: Review graphite2

2018-03-19 Thread Rene Engelhard
Hi, On Mon, Mar 19, 2018 at 04:43:51PM +0100, Markus Koschany wrote: > Am 19.03.2018 um 16:23 schrieb Rene Engelhard: > > On Sun, Mar 18, 2018 at 11:39:57AM +0530, Abhijith PA wrote: > >> I prepared LTS security update for graphite2[1]. Debdiff is attached. > >> All tes

Re: Closing of buster-backports?

2022-09-07 Thread Rene Engelhard
Hi, whatever is fine, I can live with both, but: Am 07.09.22 um 07:37 schrieb Alexander Wirt: Now that buster is LTS and no longer officially supported, should the -backports pocket be closed? AFAIK, buster just receives the security uploads by the -security pocket and shouldn't have -backports