Re: graphicsmagick packaging

2016-09-20 Thread Chris Lamb
[Not sure why I am being CC'd here?] > Is this just me? Or has graphicsmagick really been packaged without > debian/patches/*? Very likely; wheezy is old and the source/format wasn't universally adopted overnight. :) Regards, -- ,''`. : :' : Chris Lamb `. `'`

Wheezy update of firefox-esr?

2016-09-20 Thread Chris Lamb
.) Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone is registered on this update in this file: https://anonscm.debian.org/viewvc/secure-testing/data/dla

Accepted unadf 0.7.11a-3+deb7u1 (source amd64) into oldstable

2016-09-20 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Wed, 21 Sep 2016 03:27:21 +0100 Source: unadf Binary: unadf Architecture: source amd64 Version: 0.7.11a-3+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Debian QA Group <packa...@qa.debian.org> Changed-By:

Re: CVE-2016-2839 / Firefox-ESR

2016-08-17 Thread Chris Lamb
016-2839 is marked as fixed in the changelog of 45.3.0esr-1~deb7u1. Mike, as author of that changelog entry, can you comment here? Regards, -- Chris Lamb chris-lamb.co.uk / @lolamby

Re: Wheezy update of libgcrypt11?

2016-08-18 Thread Chris Lamb
age in data/dla-needed.txt. As this is an especially sensitive package, it would seem prudent to get as many eyes on your debdiffs prior to upload, either from the GnuPG maintainers and/or on the debian-lts list. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@deb

Wheezy update of chicken?

2016-08-18 Thread Chris Lamb
let us know whether you would like to review and/or test the updated package before it gets released. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone

[SECURITY] [DLA 638-1] policycoreutils security update

2016-09-25 Thread Chris Lamb
s required for the basic operation of an SELinux-based system. For Debian 7 "Wheezy", this issue has been fixed in policycoreutils version 2.1.10-9+deb7u1. We recommend that you upgrade your policycoreutils packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'`

Re: boot problem after updating dropbear

2016-09-26 Thread Chris Lamb
up files aren't available. "All sorts of stuff" … ? Can you elaborate? This would seem the key to diagnosing your issue and/or the regression here. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

[SECURITY] [DLA 688-1] cairo security update

2016-10-28 Thread Chris Lamb
generate invalid pointers from a _cairo_image_surface in write_png. For Debian 7 "Wheezy", this issue has been fixed in cairo version 1.12.2-3+deb7u1. We recommend that you upgrade your cairo packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@

Wheezy update of potrace?

2016-11-10 Thread Chris Lamb
very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone is registered on this update in this file: https://anonscm.debian.org/viewvc/secure-testing/data/dla-needed.txt?view

Accepted libxfixes 1:5.0-4+deb7u2 (source amd64) into oldstable

2016-10-14 Thread Chris Lamb
Strike Force <debia...@lists.debian.org> Changed-By: Chris Lamb <la...@debian.org> Description: libxfixes-dev - X11 miscellaneous 'fixes' extension library (development headers) libxfixes3 - X11 miscellaneous 'fixes' extension library libxfixes3-dbg - X11 miscellaneous 'fixes' exten

[SECURITY] [DLA 654-1] libxfixes security update

2016-10-14 Thread Chris Lamb
server, getting out of sync. For Debian 7 "Wheezy", this issue has been fixed in libxfixes version 1:5.0-4+deb7u2. We recommend that you upgrade your libxfixes packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

Wheezy update of mysql-connector-python?

2016-10-22 Thread Chris Lamb
also take it as an opt-out, too.) Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone is registered on this update in this file: https://anonscm.debian.org/viewvc

Wheezy update of sendmail?

2016-10-23 Thread Chris Lamb
you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone is registered on this update in this file: https://anonscm.debian.org/viewvc/secure-testing/data/dla-needed.txt?view

Accepted quagga 0.99.22.4-1+wheezy3+deb7u1 (source amd64 all) into oldstable

2016-10-18 Thread Chris Lamb
t;c...@debian.org> Changed-By: Chris Lamb <la...@debian.org> Description: quagga - BGP/OSPF/RIP routing daemon quagga-dbg - BGP/OSPF/RIP routing daemon (debug symbols) quagga-doc - documentation files for quagga Closes: 841162 Changes: quagga (0.99.22.4-1+wheezy3+deb7u1) wheezy-secur

[SECURITY] [DLA 662-1] quagga security update

2016-10-18 Thread Chris Lamb
size specified when receiving mixed up two constants that have different values. For Debian 7 "Wheezy", this issue has been fixed in quagga version 0.99.22.4-1+wheezy3+deb7u1. We recommend that you upgrade your quagga packages. Regards, - -- ,''`. : :' :

Wheezy update of guile-2.0?

2016-10-18 Thread Chris Lamb
.) Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone is registered on this update in this file: https://anonscm.debian.org/viewvc/secure-testing/data/dla-needed.txt?view

Accepted libsoap-lite-perl 0.714-1+deb7u1 (source all) into oldstable

2016-11-25 Thread Chris Lamb
ain...@lists.alioth.debian.org> Changed-By: Chris Lamb <la...@debian.org> Description: libsoap-lite-perl - Perl implementation of a SOAP client and server Changes: libsoap-lite-perl (0.714-1+deb7u1) wheezy-security; urgency=high . * CVE-2015-8978: Prevent "Billion Laughs"

[SECURITY] [DLA 723-1] libsoap-lite-perl security update

2016-11-25 Thread Chris Lamb
/wiki/SOAP Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlg4uTQACgkQHpU+J9Qx HliUtxAAt6d/d7Brm33ckLHDvvuefkP49cu94ombualj/pkHrdg7dgRiUcxvhMIO pqomm/jcnQpg1YbPmCCa/VXAd7D

Re: RFC - ImageMagick, proper testing, and handling issues without a CVE ID

2016-11-28 Thread Chris Lamb
Guido Günther wrote: > If you're asking for code review posting a debdiff to the list might > help people to pick it up. Naive diffoscope output of the two .dscs: https://gist.github.com/lamby/70610714ff448db0be955c888ffaff06/raw Regards, -- ,''`. : :' : Chri

[SECURITY] [DLA 713-1] sniffit security update

2016-11-21 Thread Chris Lamb
specially-crafted configuration file to provide a root shell. For Debian 7 "Wheezy", this issue has been fixed in sniffit version 0.3.7.beta-16.1+deb7u1. We recommend that you upgrade your sniffit packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la..

Accepted sniffit 0.3.7.beta-16.1+deb7u1 (source amd64) into oldstable

2016-11-21 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Mon, 21 Nov 2016 09:23:30 +0100 Source: sniffit Binary: sniffit Architecture: source amd64 Version: 0.3.7.beta-16.1+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: William Vera <bi...@billy.com.mx> Changed-By:

Wheezy update of tiff?

2016-11-12 Thread Chris Lamb
. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone is registered on this update in this file: https://anonscm.debian.org/viewvc/secure-testing/data/dla-needed.txt?view=markup

Re: Wheezy update of sendmail?

2016-11-01 Thread Chris Lamb
I forgot to push. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Accepted bsdiff 4.3-14+deb7u1 (source amd64) into oldstable

2016-11-03 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Thu, 03 Nov 2016 11:22:12 + Source: bsdiff Binary: bsdiff Architecture: source amd64 Version: 4.3-14+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Jari Aalto <jari.aa...@cante.net> Changed-By: Chris La

Re: python-django and CVE-2016-9014

2016-11-04 Thread Chris Lamb
egards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Accepted mcabber 0.10.1-3+deb7u1 (source amd64) into oldstable

2016-11-27 Thread Chris Lamb
hanged-By: Chris Lamb <la...@debian.org> Description: mcabber- small Jabber (XMPP) console client Closes: 845258 Changes: mcabber (0.10.1-3+deb7u1) wheezy-security; urgency=high . * Prevent a "roster push attack" [0]. This is identical to CVE-2015-8688 for gajim. (Closes:

Wheezy update of qemu?

2016-12-08 Thread Chris Lamb
the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of qemu updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might

Wheezy update of zlib?

2016-12-08 Thread Chris Lamb
the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of zlib updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might

Wheezy update of unzip?

2016-12-08 Thread Chris Lamb
the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of unzip updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might

Accepted roundcube 0.7.2-9+deb7u5 (source all) into oldstable

2016-12-08 Thread Chris Lamb
Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintain...@lists.alioth.debian.org> Changed-By: Chris Lamb <la...@debian.org> Description: roundcube - skinnable AJAX based webmail solution for IMAP servers - metapack roundcube-core - skinnable AJAX based webmail solution for

[SECURITY] [DLA 738-1] spip security update

2016-12-08 Thread Chris Lamb
attackers to inject arbitrary web script or HTML via the "rac" parameter. For Debian 7 "Wheezy", this issue has been fixed in spip version 2.1.17-1+deb7u7. We recommend that you upgrade your spip packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'`

Accepted spip 2.1.17-1+deb7u7 (source all) into oldstable

2016-12-08 Thread Chris Lamb
org> Changed-By: Chris Lamb <la...@debian.org> Description: spip - website engine for publishing Closes: 847156 Changes: spip (2.1.17-1+deb7u7) wheezy-security; urgency=high . * CVE-2016-9152: Fix cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php which al

Re: testing php5 for Wheezy LTS

2016-12-10 Thread Chris Lamb
ven't tested any the individual exploits.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Wheezy update of jasper?

2016-12-10 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of jasper updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team

Re: Wheezy update of unzip?

2016-12-09 Thread Chris Lamb
Santiago Vila wrote: > I'd like to fix this in unstable first, then I guess it would be a > little easier for you to make the update for wheezy. Is that ok? Perfect. Many thanks. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Wheezy update of roundcube?

2016-12-07 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of roundcube updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

[SECURITY] [DLA 734-1] mapserver security update

2016-12-07 Thread Chris Lamb
heezy", this issue has been fixed in mapserver version 6.0.1-3.2+deb7u3. We recommend that you upgrade your mapserver packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP

Re: Fixing CVE-2016-9839 for mapserver in wheezy

2016-12-07 Thread Chris Lamb
onfirm whether you will be generating a DLA and sending it to debian-lts-announce or not? No obligation whatsoevr just let me know either way otherwise I am waiting for your reply to avoid duplicating it myself. After announcing it, I will mark it as fixed. Regards, -- ,''`. : :' :

Re: Fixing CVE-2016-9839 for mapserver in wheezy

2016-12-06 Thread Chris Lamb
egards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Wheezy update of html5lib?

2016-12-06 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of html5lib updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

Wheezy update of libgsf?

2016-12-11 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of libgsf updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team

Wheezy update of xrdp?

2016-12-11 Thread Chris Lamb
the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of xrdp updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might

[SECURITY] [DLA 740-1] libgsf security update

2016-12-11 Thread Chris Lamb
packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlhNoJYACgkQHpU+J9Qx HlijtQ//bolNntRESdaKd1VDlyo1MG4gJ+V/gSatpS7h/kMFeBItKCT9py2JlVIr K8xH96uHYAMGsUHUph2kjF

Accepted libgsf 1.14.21-2.1+deb7u1 (source all amd64) into oldstable

2016-12-11 Thread Chris Lamb
: 1.14.21-2.1+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: J.H.M. Dassen (Ray) <jdas...@debian.org> Changed-By: Chris Lamb <la...@debian.org> Description: libgsf-1-114 - Structured File Library - runtime version libgsf-1-114-dbg - Structured File Library - debugging

Re: nvidia-graphics-drivers 304.134 proposed packages for wheezy-lts

2017-01-10 Thread Chris Lamb
Andreas Beckmann wrote: > I've prepared a new upstream release of the proprietary nvidia graphics > driver for wheezy-lts. This will fix several security bugs: Do you have a debdiff handy...? (Or, better still, diffoscope output.) Regards, -- ,''`. : :' : Chri

Accepted python-crypto 2.6-4+deb7u7 (source amd64 all) into oldstable

2017-01-09 Thread Chris Lamb
Urgency: high Maintainer: Sebastian Ramacher <sramac...@debian.org> Changed-By: Chris Lamb <la...@debian.org> Description: python-crypto - cryptographic algorithms and protocols for Python python-crypto-dbg - cryptographic algorithms and protocols for Python (debug extensio pytho

Re: DLA 773-1 and DLA 773-2

2017-01-09 Thread Chris Lamb
he multiprocessing library (+ /dev/shm etc.) rather than calling flake8 and that failing AFAICT I could, however skip the test on EPERM, but this issue seems like more of a buildd admin issue… ? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Re: DLA 773-1 and DLA 773-2

2017-01-09 Thread Chris Lamb
hon-crypto_2.6-4+deb7u7_amd64.changes which will skip the test on systems without a working multiprocessing. Will announce only once I see it in the archive for !amd64. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Re: DLA 773-1 and DLA 773-2

2017-01-09 Thread Chris Lamb
under non-amd64 when that's essentially totally unrelated to the CVEs here and just "working around" pbuilder. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

[SECURITY] [DLA 733-1] openafs security update

2016-12-03 Thread Chris Lamb
memory, OpenAFS directory objects are likely to contain 'dead' directory entry information. For Debian 7 "Wheezy", this issue has been fixed in openafs version 1.6.1-3+deb7u7. We recommend that you upgrade your openafs packages. Regards, - -- ,''`. : :' :

Re: Wheezy update of openafs?

2016-12-03 Thread Chris Lamb
o file a Debian bug next time. :) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Re: Missing upload for openafs?

2016-12-04 Thread Chris Lamb
used)? > > I'm asking since the *.deb, orig.targ.z, debian.targ.z and *.dsc are > in the upload queue, but not the changes. So the upload was not > processed. > > Regards, > Salvatore > Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Wheezy update of mapserver?

2016-12-06 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of mapserver updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

Wheezy update of graphicsmagick?

2016-12-05 Thread Chris Lamb
to review and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of graphicsmagick updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS

Re: monit segfault on stop and start

2016-12-06 Thread Chris Lamb
[Adding Jonas as they made the relevant upload] Hey, > monit segfault on stop and start This appears to be a regression in the latest LTS upload so pinging the relevant people. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Wheezy update of libvncserver?

2017-01-03 Thread Chris Lamb
to review and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of libvncserver updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS

[SECURITY] [DLA 777-1] libvncserver security update

2017-01-03 Thread Chris Lamb
e recommend that you upgrade your libvncserver packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlhryEoACgkQHpU+J9Qx Hlge/Q

Wheezy update of zendframework?

2017-01-05 Thread Chris Lamb
to review and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of zendframework updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS

Wheezy update of icoutils?

2017-01-05 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of icoutils updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

Wheezy update of ghostscript?

2017-01-05 Thread Chris Lamb
to review and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of ghostscript updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

Re: [pkg-php-pear] Wheezy update of zendframework?

2017-01-05 Thread Chris Lamb
Hi Markus, > zendframework < 2 *should* not be affected at all. Ah, not sure how I didn't see that! Many thanks. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Wheezy update of pcsc-lite?

2017-01-04 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of pcsc-lite updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

[SECURITY] [DLA 773-3] python-crypto regression update

2017-01-05 Thread Chris Lamb
this issue has been fixed in python-crypto version 2.6-4+deb7u6. We recommend that you upgrade your python-crypto packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP

Re: DLA 773-1 and DLA 773-2

2017-01-09 Thread Chris Lamb
n anyone on debian-lts@ help out here? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Wheezy update of w3m?

2017-01-09 Thread Chris Lamb
the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of w3m updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might

Re: Wheezy update of ghostscript?

2017-01-09 Thread Chris Lamb
- jbig2dec NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=697457 CVE-2016-9600 [Null Pointer Dereference due to missing check for UNKNOWN color space in JP2 encoder] RESERVED Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

[SECURITY] [DLA 773-1] python-crypto security update

2017-01-01 Thread Chris Lamb
kages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlho5McACgkQHpU+J9Qx HlguvBAAxvwxrC17S+UgmDkK51Ylm5i2W1suwwEvdl0uu7O+A09ok/WxPMuUWb4O Er5y38Esl88udV9AX7

Wheezy update of icedove?

2017-01-02 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of icedove updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS

Accidental imagemagick reversion in data/dla-needed.txt?

2016-12-30 Thread Chris Lamb
g-perl NOTE: no upstream fix yet for expand_external_ents but new no_xxe flag in 3.50 NOTE: could be backported (2016-12-13) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

[SECURITY] [DLA 773-2] python-crypto regression update

2017-01-04 Thread Chris Lamb
to version 2.6-4+deb7u5. We recommend that you upgrade your python-crypto packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlhtLhMACgkQHpU+J

Wheezy update of jbig2dec?

2017-01-05 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of jbig2dec updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

[SECURITY] [DLA 778-1] pcsc-lite security update

2017-01-06 Thread Chris Lamb
interface ("PC/SC"). For Debian 7 "Wheezy", this issue has been fixed in pcsc-lite version 1.8.4-1+deb7u2. We recommend that you upgrade your pcsc-lite packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

Re: Wheezy update of pcsc-lite?

2017-01-06 Thread Chris Lamb
Hi Ludovic, > I prepared a debdiff for the version present in oldstable. Thanks! After testing, would you like me to upload and announce it, etc.? Very happy to do that. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Re: DLA 773-1 and DLA 773-2

2017-01-10 Thread Chris Lamb
Hi Thomas, > Thanks to both of you Chris and Guido! No problem. Packages available now and I've just announced DLA 773-4. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

[SECURITY] [DLA 876-1] eject security update

2017-03-28 Thread Chris Lamb
setuid/setgid. For Debian 7 "Wheezy", this issue has been fixed in eject version 2.1.5+deb1+cvs20081104-13+deb7u1. We recommend that you upgrade your eject packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Accepted eject 2.1.5+deb1+cvs20081104-13+deb7u1 (source amd64) into oldstable

2017-03-28 Thread Chris Lamb
org> Changed-By: Chris Lamb <la...@debian.org> Description: eject - ejects CDs and operates CD-Changers under Linux eject-udeb - ejects CDs from d-i menu (udeb) Closes: 858872 Changes: eject (2.1.5+deb1+cvs20081104-13+deb7u1) wheezy-security; urgency=high . * CVE-2017

Accepted python3.2 3.2.3-7+deb7u1 (source all amd64) into oldstable

2017-03-25 Thread Chris Lamb
Distribution: wheezy-security Urgency: high Maintainer: Matthias Klose <d...@debian.org> Changed-By: Chris Lamb <la...@debian.org> Description: idle-python3.2 - IDE for Python (v3.2) using Tkinter libpython3.2 - Shared Python runtime library (version 3.2) python3.2 - Interactiv

Re: Wheezy update of apt-cacher?

2017-03-27 Thread Chris Lamb
line; however I will manually "version close" #858739 once it has been ACCEPTed by the archive.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Re: Wheezy update of apt-cacher?

2017-03-27 Thread Chris Lamb
Chris Lamb wrote: > (The only issue with your backport was it was missing a "Closes:" > line; however I will manually "version close" #858739 once it has > been ACCEPTed by the archive.) For my (own!) reference, I just realised I could have done something

Re: Wheezy update of apt-cacher?

2017-03-27 Thread Chris Lamb
rds, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

[SECURITY] [DLA 873-1] apt-cacher security update

2017-03-27 Thread Chris Lamb
heezy", this issue has been fixed in apt-cacher version 1.7.6+deb7u1. We recommend that you upgrade your apt-cacher packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP

[SECURITY] [DLA 864-1] jhead security update

2017-03-22 Thread Chris Lamb
attackers were able to execute arbitrary code via crafted image data. For Debian 7 "Wheezy", this issue has been fixed in jhead version 1:2.95-1+deb7u1. We recommend that you upgrade your jhead packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@

[SECURITY] [DLA 865-1] suricata security update

2017-03-22 Thread Chris Lamb
d that you upgrade your suricata packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAljS+o0ACgkQHpU+J

Accepted suricata 1.2.1-2+deb7u1 (source amd64) into oldstable

2017-03-22 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Wed, 22 Mar 2017 22:21:55 + Source: suricata Binary: suricata Architecture: source amd64 Version: 1.2.1-2+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Pierre Chifflier <pol...@debian.org> Changed-By:

[SECURITY] [DLA 863-1] deluge security update

2017-03-19 Thread Chris Lamb
Bittorrent client. For Debian 7 "Wheezy", this issue has been fixed in deluge version 1.3.3-2+nmu1+deb7u1. We recommend that you upgrade your deluge packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Re: Wheezy update of ioquake3?

2017-03-15 Thread Chris Lamb
egards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Re: can someone please give me a DLA number…?! (Re: Bug#856539: updating sitesummary in stable+oldtable due to regression introduced with apache update (Re: Bug#856539: jessie-pu: package sitesummary/

2017-03-18 Thread Chris Lamb
so I would need to clone it > again, which means downloading gigabytes and waiting hours. IIRC you can do a shallow git-svn clone; I'm sure someone will chime in with the incantation. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Wheezy update of chicken?

2017-03-18 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of chicken updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS

Wheezy update of git?

2017-03-20 Thread Chris Lamb
the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of git updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team might

Wheezy update of partclone?

2017-03-17 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of partclone updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

Wheezy update of ioquake3?

2017-03-15 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of ioquake3 updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

Wheezy update of libarchive?

2017-04-03 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of libarchive updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

Wheezy update of yaml-cpp?

2017-04-03 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of yaml-cpp updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team

Wheezy update of proftpd-dfsg?

2017-04-05 Thread Chris Lamb
and/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of proftpd-dfsg updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member

Accepted python-django 1.4.22-1+deb7u3 (source all) into oldstable

2017-04-05 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Wed, 05 Apr 2017 10:34:27 +0200 Source: python-django Binary: python-django python-django-doc Architecture: source all Version: 1.4.22-1+deb7u3 Distribution: wheezy-security Urgency: high Maintainer: Chris Lamb <la...@debian.

[SECURITY] [DLA 892-1] libnl3 security update

2017-04-10 Thread Chris Lamb
Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAljru3cACgkQHpU+J9Qx HliUxA/9GbQaKd86uVcwkq9zvkj2ZawG0bWmxVGsrWHet+P3T4oOcE

[SECURITY] [DLA 891-1] libnl security update

2017-04-10 Thread Chris Lamb
eb7u1. We recommend that you upgrade your libnl packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAljrut4ACgkQHpU+J9Qx Hljv4A//fNd

Accepted libnl 1.1-7+deb7u1 (source amd64 all) into oldstable

2017-04-10 Thread Chris Lamb
hanged-By: Chris Lamb <la...@debian.org> Description: libnl-dev - development library and headers for libnl libnl-doc - API documentation for libnl libnl1 - library for dealing with netlink sockets Changes: libnl (1.1-7+deb7u1) wheezy-security; urgency=high . * CVE-2017-0

[SECURITY] [DLA 882-1] tryton-server security update

2017-04-04 Thread Chris Lamb
heezy", this issue has been fixed in tryton-server version 2.2.4-1+deb7u4. We recommend that you upgrade your tryton-server packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- -BEGIN PGP

<    1   2   3   4   5   6   7   8   9   10   >