LTS meeting notes

2024-09-26 Thread Roberto C . Sánchez
http://meetbot.debian.net/debian-lts/2024/debian-lts.2024-09-26-14.00.log.html Regards, -Roberto -- Roberto C. Sánchez

Re: Security support for pypy and jython

2024-09-04 Thread Roberto C . Sánchez
bian.org/1053462 would help to better understand the > status of such packages. > > If there are no objections, I will create a MR to move python2.7, pypy > and jython from security-support-limited.deb11 to > security-support-ended.11. > I agree with moving python2.7, pypy, and jython from limited to ended. Regards, -Roberto -- Roberto C. Sánchez

Re: Move tasks from salsa to gitlab?

2024-08-22 Thread Roberto C . Sánchez
utomation) failing autopkgtest: reported autopkgtest failures need to be tested in two ways; first, they must be confirmed to still be present when building on buster, and second, the bullseye version must be built on bullseye to see if the autopkgtest for that package on bullseye is working

LTS meeting notes

2024-08-22 Thread Roberto C . Sánchez
/pad.riseup.net/p/lts-meeting-agenda Thanks again to everyone for participating. Regards, -Roberto -- Roberto C. Sánchez

Re: gpac end-of-life in stretch (and recommendation for buster/bullseye)

2024-08-08 Thread Roberto C . Sánchez
> Do we want to mark gpac EOL for bullseye as well? > Given the circumstances and the state of the package, yes I agree that we should move ahead with EOL. Could you file an EOL issue in GitLab? Regards, -Roberto -- Roberto C. Sánchez

LTS meeting notes

2024-06-27 Thread Roberto C . Sánchez
Hello everyone. Here are the notes from today's LTS meeting. Present: - Raphaël Hertzog - Santiago Ruano Rincón - Roberto C. Sánchez - Helmut Grohne - Thorsten Alteholz - Sylvain Beucler - Emilio Pozuelo Monfort - Bastien Roucariès - Lee Garrett Apologies: - Chris Lamb - Tobias Frost - Gu

Re: git CVE-2024-32004 & CVE-2024-32020

2024-05-31 Thread Roberto C . Sánchez
On Fri, May 31, 2024 at 10:41:44AM -0400, Roberto C. Sánchez wrote: > On Fri, May 31, 2024 at 03:05:35PM +0100, Sean Whitton wrote: > > > I also note: the commit message for the fix for CVE-2024-32465 says that > > it renders the fix for CVE-2024-32004 "somewhat redundant

Re: git CVE-2024-32004 & CVE-2024-32020

2024-05-31 Thread Roberto C . Sánchez
d without > the sort of usability regression linked above. > > Could someone review this assessment, please? > I haven't assessed this, but I will and then I will reply to this thread again with my assessment. Regards, -Roberto -- Roberto C. Sánchez

LTS meeting notes

2024-05-23 Thread Roberto C . Sánchez
http://meetbot.debian.net/debian-lts/2024/debian-lts.2024-05-23-14.00.log.html Regards, -Roberto -- Roberto C. Sánchez

LTS meeting notes

2024-04-25 Thread Roberto C . Sánchez
Hello everyone. Here are the notes from today's LTS meeting, with many thanks to Sylvain for agreeing to act as the note taker. Present: - Roberto C. Sánchez - Santiago Ruano - Stefano Rivera - Raphael Hertzog - Sean Whitton - Thorsten Alteholz - Utkarsh Gupta - Jochen Sprickerhof - Sy

Re: Remove support for nvidia-cuda-toolkit?

2024-04-15 Thread Roberto C . Sánchez
On Mon, Apr 15, 2024 at 11:32:14PM +0200, Ola Lundqvist wrote: > Hi Roberto > > Got it. I will assess. I guess also the popularity of the package > counts in this case. > Yes, the popularity of a package is a factor in the process of making an EOL decision. Regards, -Roberto

Re: Remove support for nvidia-cuda-toolkit?

2024-04-15 Thread Roberto C . Sánchez
ally being used, and then assess how those intended and actual use cases would be affected by an EOL decision. Regards, -Roberto -- Roberto C. Sánchez

Re: bind9 patch or new upstream version

2024-04-12 Thread Roberto C . Sánchez
f it happens to be the case that there is a new 9.11.x release that addresses the vulnerabilities, then that is potentially a path we could take. If there is not a 9.11.x version that we could migrate to, then we will need to carefully backport the patches and ensure that everything is rigorously tested. Regards, -Roberto -- Roberto C. Sánchez

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-04-11 Thread Roberto C . Sánchez
ussion. At this point, I don't see a good reason to continue this discussion. Let me have an opportunity to think about how the FD and triage guidelines should be articulated and then if there are still questions after that we can revisit the topic. Regards, -Roberto -- Roberto C. Sánchez

Re: How to handle freeimage package

2024-04-11 Thread Roberto C . Sánchez
happen: - what I suggested above (copy secteam decisions and move on to the next package) - dive in and start developing fixes to the individual CVEs Either way, expending the tremendous effort that we have expended on the specific triage decisions strikes me as a poor use of time. Regards, -Roberto -- Roberto C. Sánchez

Re: undetermined or postponed for freeimage?

2024-04-11 Thread Roberto C . Sánchez
be able to fix it in any case because we do not > have enough information to tell what the problem was in the first > place. > > While I'm at it I'm removing postponed tag for a few CVEs now, because > they are postponed until patches are available and now patches are > available in fedora. > Regards, -Roberto -- Roberto C. Sánchez

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-04-11 Thread Roberto C . Sánchez
's/ /\n/g' | egrep "CVE[-]${c}" | sort -u | wc -l ; done 2023: 643 2022: 962 2021: 900 2020: 1098 2019: 983 Regards, -Roberto -- Roberto C. Sánchez

Re: How to handle freeimage package

2024-04-10 Thread Roberto C . Sánchez
of course desirable, > even when upstream is dead. > Ah, thanks for the clarification. Regards, -Roberto -- Roberto C. Sánchez

Re: How to handle freeimage package

2024-04-10 Thread Roberto C . Sánchez
or me it was an "I don't want to do that right now" and I didn't work > on the package at that point, but I don't see a technical reason against > someone fixing the CVEs. > So, whoever is working on freeimage (Ola?) should take into account that this is part of what needs to be done. Regards, -Roberto -- Roberto C. Sánchez

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-04-08 Thread Roberto C . Sánchez
ts are always more verbose than "Minor issue". So, if we are applying a 'postponed' or 'ignored' tag and making an explanatory comment with it, that seems to me like just what we need to be doing. Do you think that this would be sufficient? Or did I miss something that would make the use of high/medium/low priorities potentially beneficial? This proposal came out of the discussion from when I first started this thread nearly a month ago. That is to say, it was after a substantial discussion had already developed. I am inclined to prefer a simpler approach and the fewer triage states that we have to manage, the better. Regards, -Roberto -- Roberto C. Sánchez

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-03-23 Thread Roberto C . Sánchez
m not certain where we would keep track of these packages which need work but perhaps not directly for a DLA. Regards, -Roberto -- Roberto C. Sánchez

Re: Expanding the scope (slightly) of dla-needed.txt

2024-03-23 Thread Roberto C . Sánchez
Regards, -Roberto -- Roberto C. Sánchez

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-03-18 Thread Roberto C . Sánchez
On Mon, Mar 18, 2024 at 01:01:28PM +0100, Emilio Pozuelo Monfort wrote: > On 14/03/2024 21:36, Roberto C. Sánchez wrote: > > - if a CVE is 'fixed' in LTS but 'ignored' in (old)stable, then the > >security team should be contacted to see if they would be will

Re: Expanding the scope (slightly) of dla-needed.txt

2024-03-15 Thread Roberto C . Sánchez
On Fri, Mar 15, 2024 at 11:06:10AM +0100, Raphael Hertzog wrote: > Hello Roberto, > > On Thu, 14 Mar 2024, Roberto C. Sánchez wrote: > > Santiago and I are in agreement that at the moment the best available > > option is to use dla-needed.txt even for tracking work that need

Expanding the scope (slightly) of dla-needed.txt

2024-03-14 Thread Roberto C . Sánchez
- FD should be confirming that package removals from dla-needed.txt are valid (i.e., that the package does not require any work towards an upload to (old)stable) Your help with this is very much appreciated. Regards, -Roberto -- Roberto C. Sánchez

Guidance for CVE triage and listing packages in dla-needed.txt

2024-03-14 Thread Roberto C . Sánchez
information.en.html#limited-security-support [1] https://salsa.debian.org/lts-team/lts-extra-tasks/-/issues/60 [2] https://lists.debian.org/debian-lts/2023/12/msg00035.html Regards, -Roberto -- Roberto C. Sánchez

Re: Remove support for nvidia-cuda-toolkit?

2024-03-12 Thread Roberto C . Sánchez
ssue in the lts-team/lts-updates-tasks project on Salsa, using the "Proposed EOL of package" issue template. Regards, -Roberto -- Roberto C. Sánchez

Re: Removed docker.io from dla-needed. Objections?

2024-03-09 Thread Roberto C . Sánchez
r, that is not the case here. That said, if someone were inclined to work on the no-dsa CVEs (assuming that there are not other higher priority tasks), then that is fine as well. Regards, -Roberto -- Roberto C. Sánchez

LTS meeting notes: 2024-02-22

2024-02-22 Thread Roberto C . Sánchez
Hello everyone. Here are the notes from the LTS meeting held today via Jitsi: Present: - Roberto C. Sánchez - Santiago Ruano - Raphael Hertzog - Stefano Rivera - Sylvain Beucler - Bastien Roucaries - Santiago - Helmut - Thorsten - Chris Lamb - Guilhem - Utkarsh Apologies: - Tobias Frost - Holger

Re: Linux Pro Magazine article on Debian LTS

2024-01-29 Thread Roberto C . Sánchez
On Wed, Jan 24, 2024 at 03:19:27PM -0500, Roberto C. Sánchez wrote: > On Tue, Jan 23, 2024 at 02:30:27PM -0800, Bruce Byfield wrote: > > > > I will need answers by Monday, January 29. Please cc to bbyfi...@axion.net. > > If > > you want a hardcopy of the issue the co

Re: debian 10 security firefox-esr upgrade failing

2024-01-28 Thread Roberto C . Sánchez
if you don't need all the language packs, then go ahead and uninstall them and you should stop getting the annoying message about packages being held back. Regards, -Roberto -- Roberto C. Sánchez

Re: debian 10 security firefox-esr upgrade failing

2024-01-28 Thread Roberto C . Sánchez
not sure why you need 66 different langauges, but that should not interfere with apt. What is the output of 'apt-cache policy firefox-esr-l10n-zh-tw'? Regards, -Roberto -- Roberto C. Sánchez

Re: debian 10 security firefox-esr upgrade failing

2024-01-28 Thread Roberto C . Sánchez
third-party source in the mix (dbeaver.io) and since you didn't provide the output of 'apt-get -s upgrade' it isn't clear what influence (if any) the presence of that source is having on the situation. Please provide the full output so that we can help you determine what is going on. Regards, -Roberto -- Roberto C. Sánchez

Re: debian 10 security firefox-esr upgrade failing

2024-01-27 Thread Roberto C . Sánchez
mmand? apt-cache policy firefox-esr Also, what is the full output of the failing installation command that you attempted? Regards, -Roberto -- Roberto C. Sánchez

Re: Linux Pro Magazine article on Debian LTS

2024-01-24 Thread Roberto C . Sánchez
in the > rest > of the world. > I am working on getting the responses put together. Regards, -Roberto -- Roberto C. Sánchez

Re: Linux Pro Magazine article on Debian LTS

2024-01-22 Thread Roberto C . Sánchez
I act as the coordinator for the LTS team and I would be the primary POC for this sort of inquiry. That said, I would prefer if you could post your questions to this list, unless for some reason you are not able to post your questions to a public list. Regards, -Roberto -- Roberto C. Sánchez

Re: Make stable-security build logs public after embargo

2023-12-11 Thread Roberto C . Sánchez
of my > work on LTS. > > Do you think this can be achieved, and how? > Has there been any progress or discussion regarding this? The LTS team will be responsible for bullseye starting in August and it would be beneficial if there could be a resolution to this. Is there anything that we could do from our side to help move things along? Regards, -Roberto -- Roberto C. Sánchez

Re: upcoming changes of the web pages /security and /lts/security

2023-12-08 Thread Roberto C . Sánchez
for a formal announcement to let us know that these should no longer be generated when a DLA is released? Regards, -Roberto -- Roberto C. Sánchez

LTS meeting schedule for 2024 has been published

2023-12-04 Thread Roberto C . Sánchez
earlier to December 19th (similar to what we are doing with the December 2023 meeting). [0] https://lts-team.pages.debian.net/wiki/Meetings.html -- Roberto C. Sánchez

Re: [SECURITY] [DLA 3676-1] horizon security update

2023-11-30 Thread Roberto C . Sánchez
On Fri, Dec 01, 2023 at 02:05:42AM +0100, Guilhem Moulin wrote: > On Thu, 30 Nov 2023 at 19:47:42 -0500, Roberto C. Sánchez wrote: > > Yes, I would recommend two things. > > Done, thanks Roberto! > You're welcome! -- Roberto C. Sánchez

LTS meeting summary and notes

2023-11-30 Thread Roberto C . Sánchez
http://meetbot.debian.net/debian-lts/2023/debian-lts.2023-11-30-13.57.txt Log: http://meetbot.debian.net/debian-lts/2023/debian-lts.2023-11-30-13.57.log.html Regards, -Roberto -- Roberto C. Sánchez

Re: [SECURITY] [DLA 3676-1] horizon security update

2023-11-30 Thread Roberto C . Sánchez
1. A new announcement has been sent under the correct reference ID. ====== Regards, -Roberto -- Roberto C. Sánchez

Re: Fix for CVE-2020-25648 in nss

2023-10-27 Thread Roberto C . Sánchez
returning SECSuccess and that that added code is where the SSL_ERROR_RX_MALFORMED_CHANGE_CIPHER value is set, all of that makes me think that my theory is a likely explanation for your unexpected test failure. Regards, -Roberto [0] https://hg.mozilla.org/projects/nss/rev/57bbefa793232586d27cee83e74411171e128361 -- Roberto C. Sánchez

Re: LTS meeting summary and notes

2023-10-26 Thread Roberto C . Sánchez
ty updates can pass unstable within a day. > Uploads to unstable require maintainer coordination. That alone has the potential to introduce a delay (e.g., in the case of an unresponsive maintainer). Perhaps "potential delays" would have been a better phrasing than "substantial delays". Regards, -Roberto -- Roberto C. Sánchez

LTS meeting summary and notes

2023-10-26 Thread Roberto C . Sánchez
OFTC. As always, note your agenda items here: https://pad.riseup.net/p/lts-meeting-agenda Regards, -Roberto -- Roberto C. Sánchez

Re: Ring

2023-10-10 Thread Roberto C . Sánchez
On Tue, Oct 10, 2023 at 09:53:58AM +, Bastien Roucariès wrote: > Le vendredi 6 octobre 2023, 19:31:43 UTC Roberto C. Sánchez a écrit : > > > > The older pjsip located in that project lacks ssl_sock_imp_common.c but > > has the other two files. Most of the remainder

Re: Ring

2023-10-06 Thread Roberto C . Sánchez
ps it would be worthwhile to find out from Thorsten (who prepared the most recent update) why that decision was made. Regards, -Roberto [0] https://github.com/savoirfairelinux/pjproject/commit/d5f95aa066f878b0aef6a64e60b61e8626e664cd -- Roberto C. Sánchez ◈ Freexian SARL https://www.free

Re: Call for tests/review: glib2.0/buster

2023-09-01 Thread Roberto C . Sánchez
On Fri, Sep 01, 2023 at 08:59:50PM +0200, Sylvain Beucler wrote: > Hi, > > On 30/08/2023 02:13, Roberto C. Sánchez wrote: > > On Sun, Aug 20, 2023 at 06:53:54PM -0300, Santiago Ruano Rincón wrote: > > > Dear all > > > > > > I've prepared a glib2.

Re: Call for tests/review: glib2.0/buster

2023-08-29 Thread Roberto C . Sánchez
update? Regards, -Roberto -- Roberto C. Sánchez

Re: bullseye / libgdbm6:amd64 is a catastrophgy

2023-08-26 Thread Roberto C . Sánchez
On Fri, Aug 25, 2023 at 11:02:35PM -0400, Chris Frey wrote: > On Fri, Aug 25, 2023 at 07:02:07AM -0400, Roberto C. Sánchez wrote: > > To claim that "because this bug affects me, it *must* be > > fixed, even when it does not meet the criteria for a normal security bug > &g

Re: bullseye / libgdbm6:amd64 is a catastrophgy

2023-08-25 Thread Roberto C . Sánchez
at it is normal "security" uploads only (which, as already stated, can occasionally include some non-security bug fixes but generally not). Regards, -Roberto -- Roberto C. Sánchez

Re: bullseye / libgdbm6:amd64 is a catastrophgy

2023-08-25 Thread Roberto C . Sánchez
or the rather robust process that we try to utilize to ensure that we properly balance the needs of everyone involved. Regards, -Roberto -- Roberto C. Sánchez

Re: bullseye / libgdbm6:amd64 is a catastrophgy

2023-08-25 Thread Roberto C . Sánchez
ansition to LTS. Once that happens there will be no further point releseas, only security updates. You should not expect that this bug will be fixed in bullseye. Regards, -Roberto -- Roberto C. Sánchez

New LTS Coordinator email alias

2023-08-23 Thread Roberto C . Sánchez
which might not be appropriate for a public mailing list can be directed to the coordinator email address. Regards, -Roberto -- Roberto C. Sánchez signature.asc Description: PGP signature

[LTS meeting agenda item] LTS workflow updates

2023-08-14 Thread Roberto C . Sánchez
ged by one of these tickets and/or if you have comments/ideas/thoughts related to the experiment or the overall concept, please feel free to bring them up. Regards, -Roberto -- Roberto C. Sánchez

Re: firefox on buster

2023-08-08 Thread Roberto C . Sánchez
quite as quick as a normal update for us (since the unstable packaging work wouldn't have been done on it, as the maintainer already moved to the next version), but is still much quicker than waiting on the toolchain stuff Regards, -Roberto -- Roberto C. Sánchez

Re: MariaDB 10.3.39

2023-07-04 Thread Roberto C . Sánchez
7;t support a straightforward backoport), and then we would have to decide at that point whether to try to apply the strategy using 10.5 as a source branch, or to migrate to a newer version altogether. Regards, -Roberto -- Roberto C. Sánchez

Re: Request for suggestions/opinion about triaging decision for renderdoc

2023-06-17 Thread Roberto C . Sánchez
ing to work" or "no, that doesn't seem feasible and the latest upstream release might be the only viable route") and then perhaps offer to assist with the work. Regards, -Roberto -- Roberto C. Sánchez

The state of fix for CVE-2019-8457 (especially as concerns db5.3)

2023-06-03 Thread Roberto C . Sánchez
dfsg2-1&stamp=1674044225&raw=0 -- Roberto C. Sánchez

Re: CVE-2023-25690: Apache2 mod_proxy for old(old)stable?

2023-04-20 Thread Roberto C . Sánchez
ct configuration what will be now rejected. > > I am asking the opinion of apache maintainer/security team before releasing. > > Thanks for remainder > > Bastien > Hi Philipp, To clarify, Bastien is working on a fix for CVE-2023-25690 for *both* buster and stretch. Regards, -Roberto -- Roberto C. Sánchez

Re: PostgreSQL 11.19-0+deb10u1

2023-02-10 Thread Roberto C . Sánchez
are of the paperwork just now. Regards, -Roberto -- Roberto C. Sánchez

Discussion of proposed "Package Owner" role for LTS/ELTS

2023-01-24 Thread Roberto C . Sánchez
particular individual or team and the continuity that comes with that. Attached to this email is a preliminary write up of the proposed role. If you have questions or feedback, please bring them to the IRC meeting or share them via a reply to this mail. Regards, -Roberto -- Roberto C. Sánchez Th

Re: EOL candidates for security-support-ended.deb10

2022-08-03 Thread Roberto C . Sánchez
Regards, -Roberto [0] https://lists.debian.org/debian-lts/2022/05/msg00043.html -- Roberto C. Sánchez http://people.connexer.com/~roberto http://www.connexer.com

Re: Help with imagemagick tests / build

2022-07-04 Thread Roberto C . Sánchez
On Mon, Jul 04, 2022 at 02:23:37PM +0200, Andreas Rönnquist wrote: > On Sun, 3 Jul 2022 17:59:53 -0400 > Roberto C. Sánchez wrote: > > >On Sat, Jul 02, 2022 at 01:30:26AM +0200, Andreas Rönnquist wrote: > >> Hello - > >> > >> I have updated the image

Re: Help with imagemagick tests / build

2022-07-03 Thread Roberto C . Sánchez
like this: if (n > 0) { ... if (svg_info->parser == (xmlParserCtxtPtr) NULL) { ... } } I suspect that may have something to do with the test failures you are observing. It may be necessary to correct the patch and upload again. Regards, -Roberto -- Roberto C. Sánchez

Re: How to interpret packages-to-support

2022-05-20 Thread Roberto C . Sánchez
has decided to drop. The LTS triage script retrieves the current list from debian-security-support package, so it should point out which packages are EOL or have limited security support. All other packages are supported as usual. Regards, -Roberto -- Roberto C. Sánchez

What is going on with debian-security-support in stretch?

2022-05-20 Thread Roberto C . Sánchez
d by a DLA (example [0]). If there are no objections, I will go ahead and do this in two or three days. If anyone has any comments or feedback, those would be welcome. Regards, -Roberto [0] https://lists.debian.org/debian-lts-announce/2020/02/msg00011.html -- Roberto C. Sánchez

gpac end-of-life in stretch (and recommendation for buster/bullseye)

2022-05-20 Thread Roberto C . Sánchez
/debian-lts/2022/04/msg8.html [1] https://salsa.debian.org/debian/debian-security-support/-/commit/0a6147d6b88d7c19ee7c072a344bbb63a7b1f32c -- Roberto C. Sánchez

Re: How to handle gpac?

2022-04-27 Thread Roberto C . Sánchez
Thanks to those who responded. I will go ahead and start working with the security team on declaring gpac EOL. Regards, -Roberto On Thu, Apr 14, 2022 at 11:11:52AM -0400, Roberto C. Sánchez wrote: > Hello everyone, > > I've been working on gpac vulnerabilities. The situation

How to handle gpac?

2022-04-14 Thread Roberto C . Sánchez
reciated. Regards, -Roberto [0] https://tracker.debian.org/pkg/gpac -- Roberto C. Sánchez

Re: Propose to ignore libxstream-java CVEs

2021-09-23 Thread Roberto C . Sánchez
gly problematic. I imagine that upstream support for security vulnerabilities associated with the old approach will either be significantly reduced or just not even there. It seems sensible to make the change now, rather than later after enduring lots more pain trying to hang on to the current approach. Regards, -Roberto -- Roberto C. Sánchez

Re: Tracking related source packages (new tool)

2021-08-30 Thread Roberto C . Sánchez
On Mon, Aug 30, 2021 at 10:57:59AM +0200, Sylvain Beucler wrote: > Hi Roberto, > > Thanks for your thorough review :) > I answer a couple comments below: > > On 29/08/2021 05:08, Roberto C. Sánchez wrote: > > On Sat, Aug 28, 2021 at 08:30:56PM +0200, Sylvain Beucler wro

Re: Tracking related source packages (new tool)

2021-08-28 Thread Roberto C . Sánchez
E/list split is implemented that this would be another tool that requires updating to deal with the new architecture. I wonder if it makes sense to proceed with implementing a "list of filenames" that the script operates upon for each parameter (e.g., CVE, DSA, DLA, etc.) in order to be ready for the coming change. Regards, -Roberto -- Roberto C. Sánchez

Re: always check and update (d|e)la-needed.txt (Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do))

2021-08-09 Thread Roberto C . Sánchez
On Mon, Aug 09, 2021 at 10:52:00AM +, Holger Levsen wrote: > Hi Roberto, > > On Mon, Aug 09, 2021 at 06:38:15AM -0400, Roberto C. Sánchez wrote: > > It was completely my fault. [...] > > Mistakes happen, thank you for owning yours! > > > The update to dla-nee

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2021-08-09 Thread Roberto C . Sánchez
On Mon, Aug 09, 2021 at 10:32:54AM +, Holger Levsen wrote: > On Mon, Aug 09, 2021 at 06:20:43AM -0400, Roberto C. Sánchez wrote: > > On Mon, Aug 09, 2021 at 08:43:34AM +, Holger Levsen wrote: > > > today three packages were unclaimed for LTS: > > > - openjdk-

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2021-08-09 Thread Roberto C . Sánchez
red the upload, and the packages were literally in the process of uploading when I saw this message. I will publish the advisories in a few hours, after all the binary packages are built. Regards, -Roberto -- Roberto C. Sánchez

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2021-02-01 Thread Roberto C . Sánchez
On Mon, Feb 01, 2021 at 11:32:13AM +, Holger Levsen wrote: > > One DLA has been reserved but not yet been published: > - DLA 2537-1 (31 Jan 2021) (ffmpeg) > It looks like this was just merged/published. > Have a great week! > You too! Regards, -Roberto -- Roberto C. Sánchez

Re: Regression in lxml in buster/stretch

2020-12-18 Thread Roberto C . Sánchez
On Fri, Dec 18, 2020 at 10:27:11AM +0100, Emilio Pozuelo Monfort wrote: > On 18/12/2020 00:05, Roberto C. Sánchez wrote: > > Uggh. If only I had waited a few more hours to upload. I have the > > advisory text ready but have not yet published the DLA. Your changes > >

Re: Suggestions for handling of condor update

2020-12-17 Thread Roberto C . Sánchez
ons. > Hi Tim, This sort of fell off my radar. Is it still possible that you might be able to review the condor updates? Regards, -Roberto -- Roberto C. Sánchez

Re: Regression in lxml in buster/stretch

2020-12-17 Thread Roberto C . Sánchez
run). > > Roberto, my changes for stretch are in [3]. Would you like to take a look at > this and finish it (probably backporting the test changes from [2]) or > should I? > Uggh. If only I had waited a few more hours to upload. I have the advisory text ready but have not yet published the DLA. Your changes for deb9u3 look good. Would you go ahead and upload deb9u3 and I will publish the advisory once it is built. Regards, -Roberto -- Roberto C. Sánchez

Re: How to handle an update that includes a regression fix and a new fix?

2020-12-15 Thread Roberto C . Sánchez
Thanks Ola and Emilio both for the helpful pointers. Regards, -Roberto On Tue, Dec 15, 2020 at 12:30:17PM +0100, Emilio Pozuelo Monfort wrote: > On 15/12/2020 02:16, Roberto C. Sánchez wrote: > > I am curious if there is a policy or best practice for how to handle a > >

How to handle an update that includes a regression fix and a new fix?

2020-12-14 Thread Roberto C . Sánchez
vulnerability fix as a subsequent update? Regards, -Roberto -- Roberto C. Sánchez

Re: Incomplete fix for CVE-2019-20218/sqlite3

2020-12-10 Thread Roberto C . Sánchez
On Thu, Dec 10, 2020 at 08:53:58AM -0500, Roberto C. Sánchez wrote: > On Tue, Dec 08, 2020 at 10:04:13AM -0500, Roberto C. Sánchez wrote: > > Hi Moritz & Chris, > > > > On Tue, Dec 08, 2020 at 02:37:14PM +, Chris Lamb wrote: > > > Hi Moritz, > >

Re: Incomplete fix for CVE-2019-20218/sqlite3

2020-12-10 Thread Roberto C . Sánchez
On Tue, Dec 08, 2020 at 10:04:13AM -0500, Roberto C. Sánchez wrote: > Hi Moritz & Chris, > > On Tue, Dec 08, 2020 at 02:37:14PM +, Chris Lamb wrote: > > Hi Moritz, > > > > > CVE-2019-20218 isn't fixed in Stretch/LTS. Running the reproducer: > >

Re: Incomplete fix for CVE-2019-20218/sqlite3

2020-12-08 Thread Roberto C . Sánchez
care. > > Roberto, can you follow-up on this? > I have claimed the package in dla-needed.txt. I will get this straightened out (including properly confirming that the vulnerability is fixed) in the coming days. Regards, -Roberto -- Roberto C. Sánchez

Re: MongoDB license change and security support

2020-11-25 Thread Roberto C . Sánchez
it is only available in stretch (LTS) and jessie (ELTS). Regards, -Roberto -- Roberto C. Sánchez

Re: MongoDB license change and security support

2020-11-25 Thread Roberto C . Sánchez
; package installed from Debian sources are really using it in a way that warrants the amount of effort that is likely to be required to continue support. To be clear, my vote would be to drop support. Regards, -Roberto -- Roberto C. Sánchez

Re: samba backport from stable/testing to oldstable.

2020-11-10 Thread Roberto C . Sánchez
bilities in stretch and I think it > > should be rolled out really soon! > Great, Thanks a lot Utkarsh for quick info. :) > Regards, > Jaikumar Utkarsh is correct. I am actively working on the update. I hope to have it completed and ready for upload this week. Regards, -Roberto -- Roberto C. Sánchez

Re: Request for patch review (brotli)

2020-11-09 Thread Roberto C . Sánchez
On Sun, Oct 25, 2020 at 02:04:30PM -0400, Roberto C. Sánchez wrote: > Hi fellow LTS folks, > > I am working on the update for brotli as it relates to CVE-2020-8927. > The upstream Git project contains a commit [0] which fixes the issue > along with several other issues in

Request for patch review (brotli)

2020-10-25 Thread Roberto C . Sánchez
reviewing so that there is not duplicate work on this. Regards, -Roberto [0] https://github.com/google/brotli/commit/223d80cfbec8fd346e32906c732c8ede21f0cea6 -- Roberto C. Sánchez http://people.connexer.com/~roberto http://www.connexer.com >From 223d80cfbec8fd346e32906c732c8ede21f0cea6 Mon Sep

Re: RFT: squid3 3.5.23-5+deb9u5, please test

2020-09-29 Thread Roberto C . Sánchez
uid3/stretch/ > > It contains fixes for CVE-2020-15049, CVE-2020-15810, CVE-2020-15811 and > CVE-2020-24606. Let me know if you find any regressions from > the current released version 3.5.23-5+deb9u4. > The changes look excellent to me. Regards, -Roberto -- Roberto C. Sánchez

Re: Thoughts on CVE-2020-15049/squid3?

2020-09-25 Thread Roberto C . Sánchez
and ela-needed.txt and also included the note from dla-needed.txt in the ela-needed.txt entry for clarity. Once you send the next RFT I will take a look. Regards, -Roberto -- Roberto C. Sánchez

Re: Thoughts on CVE-2020-15049/squid3?

2020-09-25 Thread Roberto C . Sánchez
On Fri, Sep 25, 2020 at 10:04:59PM +0200, Markus Koschany wrote: > Hello Roberto, > > Am 25.09.20 um 21:25 schrieb Roberto C. Sánchez: > > Hello fellow LTS people, > > > > I am working on an update for the squid3 package. At this time there > > are 4 open C

Thoughts on CVE-2020-15049/squid3?

2020-09-25 Thread Roberto C . Sánchez
same applies both for the package in stretch LTS and in jessie ELTS.) Regards, -Roberto -- Roberto C. Sánchez

Re: slirp / CVE-2020-7039 / CVE-2020-8608

2020-08-11 Thread Roberto C . Sánchez
, then it seems that the only viable course of action is the mark them no-dsa. Regards, -Roberto -- Roberto C. Sánchez

Re: roundcube: CVE-2020-16145: XSS vulnerability via HTML messages with malicious SVG or math content

2020-08-11 Thread Roberto C . Sánchez
On Tue, Aug 11, 2020 at 01:40:48PM -0400, Roberto C. Sánchez wrote: > On Tue, Aug 11, 2020 at 07:11:57PM +0200, Guilhem Moulin wrote: > > Dear security team, > > > > In a recent post roundcube webmail upstream has announced the following > > security fix for #9682

Re: roundcube: CVE-2020-16145: XSS vulnerability via HTML messages with malicious SVG or math content

2020-08-11 Thread Roberto C . Sánchez
x27;d appreciate if you could take care > of the DLA :-) > > Thanks! > Cheers, > -- > Guilhem. Hi Guilhem, I'll take care of it shortly. Regards, -Roberto -- Roberto C. Sánchez

Re: Suggestions for handling of condor update

2020-07-27 Thread Roberto C . Sánchez
s. > Hi Tim, I somehow missed your reply. I hope you have been able to catch up on your backlog. If I can do anything to help you with reviewing the changes, please let me know. Regards, -Roberto -- Roberto C. Sánchez

Re: Suggestions for handling of condor update

2020-07-17 Thread Roberto C . Sánchez
Condor maintainers, Could you provide your thoughts/feedback on the below? Regards, -Roberto On Sun, Jul 12, 2020 at 07:44:40AM -0400, Roberto C. Sánchez wrote: > Hello all, > > Your feedback on the condor update situation (described below) would be > appreciated. > > S

Re: Suggestions for handling of condor update

2020-07-13 Thread Roberto C . Sánchez
On Mon, Jul 13, 2020 at 10:13:34AM +0200, Sylvain Beucler wrote: > Hi Roberto, > > On 12/07/2020 13:44, Roberto C. Sánchez wrote: > > Your feedback on the condor update situation (described below) would be > > appreciated. > > > > Several weeks ago I prepared up

  1   2   3   4   5   >