NEW changes in stable-new

2016-02-28 Thread Debian FTP Masters
Processing changes file: cacti_0.8.8b+dfsg-8+deb8u4_amd64.changes ACCEPT Processing changes file: glibc_2.19-18+deb8u3_all.changes ACCEPT Processing changes file: glibc_2.19-18+deb8u3_amd64.changes ACCEPT Processing changes file: glibc_2.19-18+deb8u3_arm64.changes ACCEPT Processing changes

Processed: Re: Bug#816023: jessie-pu: package glibc/2.19-18+deb8u4

2016-02-28 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + pending Bug #816023 [release.debian.org] jessie-pu: package glibc/2.19-18+deb8u4 Added tag(s) pending. -- 816023: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816023 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#816023: jessie-pu: package glibc/2.19-18+deb8u4

2016-02-28 Thread Adam D. Barratt
Control: tags -1 + pending On Sun, 2016-02-28 at 16:20 +0100, Aurelien Jarno wrote: > On 2016-02-26 21:17, Adam D. Barratt wrote: > > Control: tags -1 + confirmed > > > > On Fri, 2016-02-26 at 19:34 +0100, Aurelien Jarno wrote: > > > I would like to do an upload of glibc in jessie to fix a

Bug#816243: jessie-pu: package subversion/1.8.10-6+deb8u3

2016-02-28 Thread James McCoy
Package: release.debian.org Severity: normal Tags: jessie User: release.debian@packages.debian.org Usertags: pu I'd like to propose the following update (+ s/UNRELEASED/jessie/) to fix a crash when running svn and using kwallet to store credentials. $ debdiff

Bug#813237: transition: ruby2.3

2016-02-28 Thread Antonio Terceiro
On Sun, Feb 28, 2016 at 10:19:51PM +0100, Emilio Pozuelo Monfort wrote: > On 28/02/16 16:26, Antonio Terceiro wrote: > > Hi, > > > > On Fri, Feb 26, 2016 at 04:27:09PM +0100, Emilio Pozuelo Monfort wrote: > >> On 26/02/16 00:47, Antonio Terceiro wrote: > >>> Some of the failures above have

Bug#810961: marked as done (transition: libquvi)

2016-02-28 Thread Debian Bug Tracking System
Your message dated Sun, 28 Feb 2016 23:54:29 +0100 with message-id <56d37aa5.8040...@debian.org> and subject line Re: Bug#810961: transition: libquvi has caused the Debian Bug report #810961, regarding transition: libquvi to be marked as done. This means that you claim that the problem has been

Dropping jasper from stretch

2016-02-28 Thread Moritz Mühlenhoff
Hi, see 812630/816228 (also discussed with Roland): Security team would to drop jasper from stretch (and eventually from the archive). Some high-profile users like gdk-pixbuf already had it dropped some time ago. Ok with the release team? Could you please setup a removal/transition tracker for

Bug#815931: transition: cfitsio

2016-02-28 Thread Emilio Pozuelo Monfort
On 26/02/16 19:17, Aurelien Jarno wrote: > Thanks, I have just uploaded the package. binNMUs scheduled. Emilio

Bug#813237: transition: ruby2.3

2016-02-28 Thread Emilio Pozuelo Monfort
On 28/02/16 16:26, Antonio Terceiro wrote: > Hi, > > On Fri, Feb 26, 2016 at 04:27:09PM +0100, Emilio Pozuelo Monfort wrote: >> On 26/02/16 00:47, Antonio Terceiro wrote: >>> Some of the failures above have already been fixed. Please binNMU the >>> following packages: >> >> Scheduled. > >

Bug#816165: marked as done (nmu: samba_2:4.3.3+dfsg-2)

2016-02-28 Thread Debian Bug Tracking System
Your message dated Sun, 28 Feb 2016 22:11:05 +0100 with message-id <56d36269.9000...@debian.org> and subject line Re: Bug#816165: nmu: samba_2:4.3.3+dfsg-2 has caused the Debian Bug report #816165, regarding nmu: samba_2:4.3.3+dfsg-2 to be marked as done. This means that you claim that the

Bug#813128: marked as done (transition: openmpi)

2016-02-28 Thread Debian Bug Tracking System
Your message dated Sun, 28 Feb 2016 21:48:16 +0100 with message-id <56d35d10.6030...@debian.org> and subject line Re: Bug#813128: transition: openmpi has caused the Debian Bug report #813128, regarding transition: openmpi to be marked as done. This means that you claim that the problem has been

Bug#816198: jessie-pu: package php-dompdf/0.6.1+dfsg-2

2016-02-28 Thread Markus Frosch
On 28.02.2016 19:42, Salvatore Bonaccorso wrote: > CVE-2014-2383 should actually be already fixed in 0.6.1+dfsg-1. Is > that wrong? > > https://security-tracker.debian.org/tracker/CVE-2014-2383 > https://bugs.debian.org/745619 Thats seems to be correct, upstream mentioned it on 0.6.2 as well.

Bug#816198: jessie-pu: package php-dompdf/0.6.1+dfsg-2

2016-02-28 Thread Salvatore Bonaccorso
Hi Markus, Just one note: On Sun, Feb 28, 2016 at 06:22:08PM +0100, Markus Frosch wrote: > +php-dompdf (0.6.1+dfsg-2+deb8u1) UNRELEASED; urgency=medium > + > + * Non-maintainer upload. > + * [22610bd] Add 0.6.2 hotfix patch (Closes: #813849) > + > +Fixes CVE: > +* CVE-2014-2383 > +

Bug#816037: Bug#816198: jessie-pu: package php-dompdf/0.6.1+dfsg-2

2016-02-28 Thread Markus Frosch
Hi Adam, On 28.02.2016 18:29, Adam D. Barratt wrote: > Well the RM's already been requested - see #816037. Could you please > sort out between you what's happening, and let us know? haven't seen that bug. I decided to take over and ITA yesterday, so that was after David's request. Since I still

Processed: Re: Bug#816198: jessie-pu: package php-dompdf/0.6.1+dfsg-2

2016-02-28 Thread Debian Bug Tracking System
Processing control commands: > tags 816198 + moreinfo Bug #816198 [release.debian.org] jessie-pu: package php-dompdf/0.6.1+dfsg-2 Ignoring request to alter tags of bug #816198 to the same tags previously set -- 816198: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816198 Debian Bug Tracking

Bug#816037: Bug#816198: jessie-pu: package php-dompdf/0.6.1+dfsg-2

2016-02-28 Thread Adam D. Barratt
Control: tags 816198 + moreinfo On Sun, 2016-02-28 at 18:22 +0100, Markus Frosch wrote: > Hey release team, > I'd like to propose an update for jessie, that addresses 4 CVEs with > php-dompdf. > > Related package bug is #813849 > > Though php-dompdf is technically a leaf package, I'd prefer to

Processed: Re: Bug#816198: jessie-pu: package php-dompdf/0.6.1+dfsg-2

2016-02-28 Thread Debian Bug Tracking System
Processing control commands: > tags 816198 + moreinfo Bug #816198 [release.debian.org] jessie-pu: package php-dompdf/0.6.1+dfsg-2 Added tag(s) moreinfo. -- 816037: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816037 816198: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816198 Debian Bug

Bug#816198: jessie-pu: package php-dompdf/0.6.1+dfsg-2

2016-02-28 Thread Markus Frosch
Package: release.debian.org Severity: normal Tags: jessie User: release.debian@packages.debian.org Usertags: pu Hey release team, I'd like to propose an update for jessie, that addresses 4 CVEs with php-dompdf. Related package bug is #813849 Though php-dompdf is technically a leaf package,

Bug#813237: transition: ruby2.3

2016-02-28 Thread Antonio Terceiro
Hi, On Fri, Feb 26, 2016 at 04:27:09PM +0100, Emilio Pozuelo Monfort wrote: > On 26/02/16 00:47, Antonio Terceiro wrote: > > Some of the failures above have already been fixed. Please binNMU the > > following packages: > > Scheduled. Thanks. All of the builds seem to have finished, but for some

Bug#816023: jessie-pu: package glibc/2.19-18+deb8u4

2016-02-28 Thread Aurelien Jarno
On 2016-02-26 21:17, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Fri, 2016-02-26 at 19:34 +0100, Aurelien Jarno wrote: > > I would like to do an upload of glibc in jessie to fix a longstanding > > security issue with the pt_chown helper (CVE-2013-2207). > [...] > > I would

Bug#816165: nmu: samba_2:4.3.3+dfsg-2

2016-02-28 Thread Andreas Beckmann
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: binnmu nmu samba_2:4.3.3+dfsg-2 . ANY . unstable . -m "Rebuild against ldb 1.1.26." samba binaries have strict dependencies on the upstream version of libldb1 used at compile time, making