Bug#1073235: bookworm-pu: package bluez/5.66-1+deb12u2

2024-06-18 Thread Moritz Muehlenhoff
On Mon, Jun 17, 2024 at 06:18:40PM +0100, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Fri, 2024-06-14 at 23:25 +0200, Moritz Muehlenhoff wrote: > > Attached debdiff fixes three minor security issues. The update > > has been tested on a Bookworm system. debdi

Bug#1073235: bookworm-pu: package bluez/5.66-1+deb12u2

2024-06-14 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: bl...@packages.debian.org, iwama...@debian.org Control: affects -1 + src:bluez User: release.debian@packages.debian.org Usertags: pu Attached debdiff fixes three minor security issues. The update has been tested on a Boo

Bug#1070175: RM: salt/3002.6+dfsg1-4+deb11u1

2024-05-01 Thread Moritz Muehlenhoff
On Wed, May 01, 2024 at 06:29:29PM +0100, Adam D. Barratt wrote: > On Wed, 2024-05-01 at 13:02 +0200, Moritz Muehlenhoff wrote: > > Please remove salt in the next Bullseye point release. > > It was already removed frm unstable for being unsupportable > > and unmaintained (htt

Bug#1070175: RM: salt/3002.6+dfsg1-4+deb11u1

2024-05-01 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal X-Debbugs-Cc: s...@packages.debian.org Control: affects -1 + src:salt User: release.debian@packages.debian.org Usertags: rm Please remove salt in the next Bullseye point release. It was already removed frm unstable for being unsupportable and unmain

Bug#1068451: bookworm-pu: package libtommath/1.2.0-6+deb12u1

2024-04-05 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: libtomm...@packages.debian.org Control: affects -1 + src:libtommath Addresses CVE-2023-36328, debdiff below. Acked by Dominique before. Cheers, Moritz diff

Re: Security releases for ecosystems that use static linking

2024-03-20 Thread Moritz Muehlenhoff
Thorsten Alteholz wrote: [ Adding DSA to the CC list ] > On Mon, 18 Mar 2024, Emilio Pozuelo Monfort wrote: > > > One solution which has been discussed in the past is to import a full copy > > > of stable towards stable-security at the beginning of each release cycle, > > > but that is currently

Re: Security releases for ecosystems that use static linking

2024-03-18 Thread Moritz Muehlenhoff
On Mon, Mar 18, 2024 at 01:13:15PM +0100, Emilio Pozuelo Monfort wrote: > [ Adding debian-dak@ to Cc ] > > One solution which has been discussed in the past is to import a full copy > > of stable towards stable-security at the beginning of each release cycle, > > but that is currently not possible

Bug#1063736: snort removal from bullseye (Re: Bug#1063736: RM: snort -- RoQA; security issues, unmaintained)

2024-02-12 Thread Moritz Muehlenhoff
On Mon, Feb 12, 2024 at 06:16:48PM +, Jonathan Wiltshire wrote: > On Mon, Feb 12, 2024 at 09:24:47AM +, Holger Levsen wrote: > > hi, > > > > On Sun, Feb 11, 2024 at 09:44:18PM +, Jonathan Wiltshire wrote: > > > Requested by security team. Not in stable or testing. > > > > once this ha

Bug#1061572: bullseye-pu: package unadf/0.7.11a-4+deb11u1

2024-01-26 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: un...@packages.debian.org Control: affects -1 + src:unadf Addresses two no-dsa security issues, same fix already rolled out for Bookworm. Debdiff below. Cheers,

Re: openjdk-8 vs. nvidia-openjdk-8-jre

2024-01-19 Thread Moritz Muehlenhoff
On Fri, Jan 19, 2024 at 02:38:32AM +, Thorsten Glaser wrote: > Hi > > TIL about the existence of nvidia-openjdk-8-jre. > > Would it not be better to drop that and remove the bug deliberately > blocking openjdk-8 from entering testing/stable? No, we have enough OpenJDK releases to look after

Bug#1059426: bookworm-pu: package haproxy/2.6.12-1+deb12u1

2023-12-25 Thread Moritz Muehlenhoff
On Mon, Dec 25, 2023 at 10:32:41AM +0100, Tobias Frost wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: hapr...@packages.debian.org > X-Debbugs-Cc: t...@security.debian.org > Control: affects -1 +

Re: Security releases for ecosystems that use static linking

2023-12-22 Thread Moritz Muehlenhoff
On Fri, Dec 22, 2023 at 10:19:15AM -0300, Santiago Ruano Rincón wrote: > El 22/12/23 a las 09:54, Moritz Muehlenhoff escribió: > > On Thu, Dec 21, 2023 at 07:30:51PM -0300, Santiago Ruano Rincón wrote: > > > So let me ask you: are you interested in addressing the infrastructure

Re: Security releases for ecosystems that use static linking

2023-12-22 Thread Moritz Muehlenhoff
On Thu, Dec 21, 2023 at 07:30:51PM -0300, Santiago Ruano Rincón wrote: > So let me ask you: are you interested in addressing the infrastructure > limitations to handle those kind of packages? and having some help for > that? Foremost this is an infrastructure limitation that needs to be resolved:

Re: Bug#1057755: Qt WebEngine Security Support In Stable

2023-12-15 Thread Moritz Muehlenhoff
On Fri, Dec 15, 2023 at 10:39:04AM +0200, Adrian Bunk wrote: > > That is a good point. However, I consider full coverage of security support > > for stable to be an improvement over the current situation. Explicitly > > stating that security support is not shipped for oldstable does not do any > >

Bug#1056696: bookworm-pu: package unadf/0.7.11a-5+deb12u1

2023-11-24 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: un...@packages.debian.org Control: affects -1 + src:unadf Fixes two minor security issues. These have actually been in past releases (wheezy/jessie), but the patch wa

Bug#1052288: bullseye-pu: package qemu/1:5.2+dfsg-11+deb11u3

2023-09-19 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: q...@packages.debian.org, m...@tls.msk.ru Control: affects -1 + src:qemu Various low severity security issues in qemu, debdiff below. I've tested this on a Bullseye g

Bug#1051232: bookworm-pu: package 7zip/23.01+dfsg-3~deb12u1

2023-09-04 Thread Moritz Muehlenhoff
On Tue, Sep 05, 2023 at 04:04:27AM +0900, YOKOTA Hiroshi wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: 7...@packages.debian.org, yokota.h...@gmail.com, > b...@debian.org, t...@security.debian.o

Bug#1051169: RM: nomad/0.12.10+dfsg1-3

2023-09-03 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Hashicorp switched to the non-free BSL and security fixes will only be made available until December 31 2023, so we should remove it with the Bullseye 11.8 point release: https://www.hashicorp.co

Bug#1051170: RM: nomad-driver-lxc/0.3.0-1

2023-09-03 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Needs to be removed alongside with nomad. Cheers, Moritz

Bug#1041498: bookworm-pu: package testng7/7.5-2~deb12u1

2023-07-19 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: test...@packages.debian.org, d...@debian.org, vladimir.pe...@canonical.com Control: affects -1 + src:testng7 We need to introduce a backport of testng7 in the versio

Bug#1041397: bookworm-pu: package asmtools/7.0-b09-2~deb11u1

2023-07-18 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: asmto...@packages.debian.org, ebo...@apache.org Control: affects -1 + src:asmtools We need to introduce a backport of asmtools in the version found in bookworm to bul

Re: tomcat9 should not be released with Bookworm

2023-05-26 Thread Moritz Muehlenhoff
On Fri, May 26, 2023 at 12:10:18AM +0200, Markus Koschany wrote: > First of all trapperkeeper-webserver-jetty9-clojure should add a build- > dependency on logback to detect such regressions in advance. > > #1036250 is mainly a logback problem, not a tomcat problem. I still would like > to hear Emm

Bug#1034798: RM: gpac/2.0.0+dfsg1-4

2023-04-24 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm X-Debbugs-Cc: g...@packages.debian.org, siret...@tauware.de, sramac...@debian.org Control: affects -1 + src:gpac In priot discussion between Reinhard, Sebastian and the Security team we've come

Bug#1032977: unblock: apache2/2.4.56-1

2023-03-18 Thread Moritz Muehlenhoff
On Sat, Mar 18, 2023 at 09:17:25AM +0100, Sebastian Ramacher wrote: > Control: tags -1 moreinfo > > Hi security team > > On 2023-03-15 06:46:32 +0400, Yadd wrote: > > Package: release.debian.org > > Severity: normal > > User: release.debian@packages.debian.org > > Usertags: unblock > > X-Debb

Bug#1032885: unblock: debian-security-support/1:12+2023.03.05

2023-03-13 Thread Moritz Muehlenhoff
On Mon, Mar 13, 2023 at 03:07:34PM +, Holger Levsen wrote: > On Mon, Mar 13, 2023 at 03:58:45PM +0100, Moritz Mühlenhoff wrote: > > Am Mon, Mar 13, 2023 at 01:43:11PM +0100 schrieb Holger Levsen: > > > * security-support-limited: > > > - for golang and openjdk-17, point to the bookworm ma

Re: testing security uploads to bookworm-security

2023-03-06 Thread Moritz Muehlenhoff
On Mon, Mar 06, 2023 at 10:17:04PM +0100, Paul Gevers wrote: > Dear security team, > > It's the time of the season to ask you to consider testing that the next > security suite is working as intended. In our checklist [1] it's mentioned > to coordinate with you an upload to bookworm-security to co

Bug#1031635: bullseye-pu: package snakeyaml/1.28-1

2023-02-27 Thread Moritz Muehlenhoff
On Fri, Feb 24, 2023 at 10:29:07PM +0100, Markus Koschany wrote: > Hi, > > Am Freitag, dem 24.02.2023 um 16:01 +0100 schrieb Moritz Mühlenhoff: > [...] > > Could we also ship the README.Debian.security that was recently added > > in unstable to bullseye/buster? > > I've just uploaded a new revisi

Bug#1004441: unblocking chromium?

2023-01-06 Thread Moritz Muehlenhoff
On Fri, Jan 06, 2023 at 08:41:50AM +0100, Paul Gevers wrote: > Dear Chromium team, Security team, > > On 27-01-2022 17:15, Moritz Muehlenhoff wrote: > > On Wed, Jan 26, 2022 at 09:38:42PM +0100, Paul Gevers wrote: > > > > So, I'm proposing the following: we unblo

Bug#1025205: bullseye-pu: package mplayer/2:1.4+ds1-1+deb11u1

2022-11-30 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu This updates fixes various minor crashes in mplayer, which don't warrant a DSA by itself. I've run the PoCs against the updated build where applicable and also tested various rando

Bug#1025010: bullseye-pu: package jtreg6/6.1+2-1~deb11u1

2022-11-28 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: d...@debian.org openjdk bumped the requirements for the test suite within their 11.x branch (which is what we ship in Bullseye), it now needs jtreg6. The debdiff is

Bug#1007931: buster-pu: package qemu/1:3.1+dfsg-8+deb10u9

2022-08-22 Thread Moritz Muehlenhoff
On Mon, Aug 22, 2022 at 02:50:41PM +0530, Abhijith PA wrote: > Hello Moritz, > > I've prepared a qemu build months back fixing pending CVEs then. I > have now took 2 patches (CVE-2020-35504, CVE-2020-35505) from your > diff and backported a new CVE, fixing total of ~35 CVEs. > > I've tested o

Bug#1007931: buster-pu: package qemu/1:3.1+dfsg-8+deb10u9

2022-03-18 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: m...@tls.msk.ru Various low severity qemu issues, but since quite a few of those have piled up, it makes sense to move to an update. Debdiff below. Cheers, Mor

Bug#1007920: buster-pu: package flac/1.3.3-2+deb11u1

2022-03-18 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: fab...@debian.org Fixes a minor security issue, debdiff below (and was just uploaded). Tested with a few sample files. Cheers, Moritz diff -Nru flac-1.3.3/de

Re: unblocking chromium?

2022-01-27 Thread Moritz Muehlenhoff
On Wed, Jan 26, 2022 at 09:38:42PM +0100, Paul Gevers wrote: > > So, I'm proposing the following: we unblock chromium from > > testing, with the understanding that prior to bookworm's release, we > > have a discussion with the release team about whether chromium will > > be allowed in the stable re

Re: chromium: Update to version 94.0.4606.61 (security-fixes)

2022-01-02 Thread Moritz Muehlenhoff
On Sat, Jan 01, 2022 at 01:23:09PM -0500, Andres Salomon wrote: > How should I handle this? NMU to sid, let people try it out, and then > deal with buster/bullseye? Yeah, let's proceed with unstable first in any case. > Upload everything all at once? I'm also > going to try building for buster, u

Re: chromium: Update to version 94.0.4606.61 (security-fixes)

2022-01-02 Thread Moritz Muehlenhoff
On Sun, Jan 02, 2022 at 06:53:51PM +0100, Mattia Rizzolo wrote: > Correlated, do you know how long do they plan on keeping using python2? > That's plainly unsuitable, it really is not going to last much longer in > debian. Current state of the Python 3 upstream migration can be found here: https:/

Re: chromium: Update to version 94.0.4606.61 (security-fixes)

2021-12-13 Thread Moritz Muehlenhoff
On Sun, Dec 12, 2021 at 08:11:00PM -0500, Andres Salomon wrote: > On 12/5/21 6:41 AM, Moritz Mühlenhoff wrote: > > Am Sun, Dec 05, 2021 at 10:53:56AM +0100 schrieb Paul Gevers: > > Exactly that. > > > > I'd suggest anyone who's interested in seeing Chromium supported to first > > update it in unst

Re: multiple RPKI-related vulnerabilities in stable

2021-11-30 Thread Moritz Muehlenhoff
Hi Marco, On Sun, Nov 28, 2021 at 11:57:09PM +0100, SEEWEB - Marco d'Itri wrote: > https://rpki.exposed/ lists a long number of vulnerabilities affecting Ironically this website is unreachable since at least yesterday :-) > It is not really practical to extract and backport all these patches, s

Bug#1000480: buster-pu: package jtharness/6.0-b15-1~deb10u1

2021-11-23 Thread Moritz Muehlenhoff
-1,3 +1,10 @@ +jtharness (6.0-b15-1~deb10u1) buster; urgency=medium + + * Rebuild for buster, needed for latest OpenJDK 11.x release +- Switch to debhelper 12 + + -- Moritz Muehlenhoff Fri, 19 Nov 2021 16:17:12 + + jtharness (6.0-b15-1) unstable; urgency=medium * Team upload.

Bug#1000479: buster-pu: package jtreg/5.1-b01-2~deb10u1

2021-11-23 Thread Moritz Muehlenhoff
-1,3 +1,10 @@ +jtreg (5.1-b01-2~deb10u1) buster; urgency=medium + + * Rebuild for buster, needed for latest OpenJDK 11.x release +- Switch to debhelper 12 + + -- Moritz Muehlenhoff Fri, 19 Nov 2021 16:26:05 + + jtreg (5.1-b01-2) unstable; urgency=medium * Team upload. diff -Nru jtreg-5.1-

Bug#991827: RM: libgrokj2k/7.6.6-3

2021-08-02 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm X-Debbugs-Cc: boxe...@gmail.com Please remove libgrokj2k/7.6.6-3 from testing (as discussed with the maintainer, also CCed). libgrokj2k is still in rapid development (upstream is already at 9.3),

Bug#991716: unblock: neomutt/20201127+dfsg.1-1.2

2021-07-30 Thread Moritz Muehlenhoff
) unstable; urgency=medium + + * Non-maintainer upload. + * Fix CVE-2021-32055 (Closes: #988107) + + -- Moritz Muehlenhoff Thu, 29 Jul 2021 23:13:20 +0200 + neomutt (20201127+dfsg.1-1.1) unstable; urgency=medium * Non-maintainer upload. diff -Nru neomutt-20201127+dfsg.1/debian/patches/series

Bug#990754: unblock: wpewebkit/2.32.1-1

2021-07-07 Thread Moritz Muehlenhoff
On Tue, Jul 06, 2021 at 10:11:36PM +0200, Sebastian Ramacher wrote: > Control: tags -1 moreinfo > > On 2021-07-06 11:20:10 +0200, Alberto Garcia wrote: > > Package: release.debian.org > > Severity: normal > > User: release.debian@packages.debian.org > > Usertags: unblock > > > > Please unbloc

Re: Bug#989839: Thunderbird 1:78.11.0-1 in testing lacks full functionality

2021-06-20 Thread Moritz Muehlenhoff
On Sat, Jun 19, 2021 at 09:33:37PM +0200, Sebastian Ramacher wrote: > Hallo Carsten > > On 2021-06-19 09:00:13 +0200, Carsten Schoenert wrote: > > Hello Kevin, hello Sebastian, > > > > thanks for working on this issue in between times, I wasn't able to do > > anything practically the last days. >

Bug#989618: unblock: libwebp/0.6.1-2.1

2021-06-08 Thread Moritz Muehlenhoff
: CVE-2018-25009, CVE-2018-25010, CVE-2018-25011 +CVE-2020-36328, CVE-2018-25013, CVE-2018-25014, CVE-2020-36329, CVE-2020-36330 +CVE-2020-36331, CVE-2020-36332 + + -- Moritz Muehlenhoff Sat, 05 Jun 2021 19:35:57 +0200 + libwebp (0.6.1-2) unstable; urgency=medium * Fix lintian warning

Bug#988746: RM: jodd/3.8.6-1.1

2021-05-18 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm X-Debbugs-Cc: ebo...@apache.org Please remove jodd from bullseye, it has open security issues and there are currently no rdeps (it was uploaded for jmeter 3, which didn't enter the archive yet).

Bug#983531: buster-pu: package python2.7/2.7.16-2+deb10u2

2021-02-26 Thread Moritz Muehlenhoff
On Fri, Feb 26, 2021 at 07:49:38AM +0100, Matthias Klose wrote: > On 2/25/21 7:41 PM, Moritz Muehlenhoff wrote: > > + * CVE-2021-3177 > > are all the ctypes tests passing with this patch? See #983516. I'll have a look at Marc' updated patch and revise if needed. Cheers, Moritz

Bug#983531: buster-pu: package python2.7/2.7.16-2+deb10u2

2021-02-25 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: d...@debian.org debdiff below fixes three security issues, which don't warrant a DSA by itself. Update has been tested on a Buster few systems (and verified with the P

Bug#983134: buster-pu: package python3.7/3.7.3-2+deb10u3

2021-02-19 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: d...@debian.org debdiff below fixes two security issues, which don't warrant a DSA by itself. Update has been tested on a Buster few systems (and verified with the PoC

Bug#976811: transition: php8.0

2021-02-07 Thread Moritz Muehlenhoff
On Sat, Feb 06, 2021 at 09:26:39PM +0100, Salvatore Bonaccorso wrote: > Otherwise there will be > expectation that both php7.4 and php8.0 will be covered by (security) > support in bullseye if we release with php8.0 included. Yeah, let's drop 8.0 then. Cheers, Moritz

Bug#981292: buster-pu: package cairo/1.16.0-4+deb10u1

2021-01-28 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: po...@debian.org Low severity security fix, synched up with Emilio on IRC for the upload. Cheers, Moritz diff -Nru cairo-1.16.0/debian/changelog cairo-1.16.0/

Re: Bug#975016: Python 2 / OpenJDK 15 support state for Bullseye

2020-11-18 Thread Moritz Muehlenhoff
On Wed, Nov 18, 2020 at 12:20:37PM +0100, Matthias Klose wrote: > [removed the Python 2 bits] > > On 11/17/20 11:08 PM, Moritz Muehlenhoff wrote: > > Package: debian-security-support > > Severity: normal > > X-Debbugs-Cc: d...@debian.org, t...@security.debian.or

Bug#974695: buster-pu: package libxml2/2.9.4+dfsg1-7+deb10u1

2020-11-13 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: mattiadebian.org This fixes a few low severity security fixes affecting libxml2, I've tested the package on a buster system with a few rdeps. Cheers, Moritz di

Bug#972183: buster-pu: package libjpeg-turbo/1:1.5.2-2+deb10u1

2020-10-13 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: ond...@debian.org, sunwea...@debian.org This fixes a number of security issues in libjpeg, which don't warrant a DSA. Package has been tested on a buster system. Cheer

Bug#972115: buster-pu: package sqlite3/3.27.2-3+deb10u1

2020-10-12 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: g...@debian.org A number of security fixes in sqlite, which don't warrant a DSA. This has been tested on a Buster system (along with validating included test cases that

Bug#972007: RM: sieve-extension/0.3.0+dfsg-1

2020-10-11 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Please remove sieve-extension in the next Buster point release, it's broken with Thunderbird 78 (the addon interface has been removed) and has already removed from unstable. Cheers, Mori

Bug#972005: RM: nostalgy/0.2.36-1.2

2020-10-11 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm X-Debbugs-Cc: a...@sigxcpu.org Please remove nostalgy in the next Buster point release, it's incompatible with Thunderbird 78 (it has already removed from unstable) Cheers, Moritz

Bug#971915: buster-pu: package transmission/2.94-2+deb10u2

2020-10-09 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: mo...@debian.org [ Reason ] Fixes a memory leak when running Transmission in daemon mode. [ Tests ] Have been using the package since a few weeks and the user who repo

Bug#971869: buster-pu: package freecol/0.11.6+dfsg2-2+deb10u1

2020-10-08 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: a...@debian.org Low severity bugfix for freecol, which doesn't warrant a DSA. The (identical) patch has been in unstable for half a year, also doublechecked by playing

Bug#971866: buster-pu: package okular/4:17.12.2-2.2+deb10u1

2020-10-08 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: p...@debian.org Low severity fix for Okular, which doesn't warrant a DSA. I've tested with the reproducerand a number of other PDF files that everything works as expect

Bug#970584: buster-pu: package inetutils/2:1.9.4-7+deb10u1

2020-09-19 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: guil...@debian.org Fix for CVE-2020-10188, which doesn' really warrant a DSA. (The numbering in debian/patches/series is the following what's in unstable, the same pat

Bug#970583: buster-pu: package chocolate-doom/3.0.0-4+deb10u1

2020-09-19 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: fab...@debian.org Fix for CVE-2020-14983, which doesn't really warrant a DSA. Debdiff attached. Cheers, Moritz diff -Nru chocolate-doom-3.0.0/debian/changelog

Bug#970564: buster-pu: package milkytracker/1.02.00+dfsg-1+deb10u1

2020-09-18 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: jcowg...@debian.org Attached debdiff fixes a few security issues in milkytracker which don't warrant a DSA. I've verified all reproducers and the (identical) patches ha

Bug#970563: buster-pu: package libx11/2:1.6.7-1+deb10u1

2020-09-18 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: jcris...@debian.org, tjaal...@debian.org This updates fixes a few security issues in libx11, which don't warrant a DSA. Debdiff attached. Cheers, Moritz diff -

Re: Go issues wrt. Debian infrastructure: moving forward

2020-08-27 Thread Moritz Muehlenhoff
On Thu, Aug 27, 2020 at 11:31:36AM +0200, Clément Hermann wrote: > >>> On Wed, Aug 26, 2020 at 12:39:36PM +0200, Clément Hermann wrote: > >>> > - a way for dak to get the orig tarball from main archive when > >>> it's not > >>> > already in the security archive (or at least, as a wo

Bug#966454: RM: golang-github-unknwon-cae/0.0~git20160715.0.c6aac99-4

2020-07-28 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Please remove 0.0~git20160715.0.c6aac99-4 from stable. There are open security issues, upstream development has stopped and there are no reverse deps. Cheers, Moritz

Bug#966272: buster-pu: package python3.7/3.7.3-2+deb10u2

2020-07-25 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Fixes three minor security issues, debdiff attached. Cheers, Moritz diff -Nru python3.7-3.7.3/debian/changelog python3.7-3.7.3/debian/changelog --- python3.7-3.7.3/debian/ch

Bug#966247: buster-pu: package commons-configuration2/2.2-1+deb10u1

2020-07-25 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Fixes a minor security issue, debdiff below. Cheers, Moritz diff -Nru commons-configuration2-2.2/debian/changelog commons-configuration2-2.2/debian/changelog --- commons-c

Bug#966213: buster-pu: package pillow/5.4.1-2+deb10u2

2020-07-24 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu A few non-severe security issues, debdiff below. Cheers, Moritz diff -Nru pillow-5.4.1/debian/changelog pillow-5.4.1/debian/changelog --- pillow-5.4.1/debian/changelog

Bug#964868: stretch-pu: package transmission/2.94-2+deb10u1

2020-07-11 Thread Moritz Muehlenhoff
+0200 @@ -1,3 +1,9 @@ +transmission (2.94-2+deb10u1) buster; urgency=medium + + * CVE-2018-10756 (Closes: #961461) + + -- Moritz Muehlenhoff Fri, 29 May 2020 00:05:53 +0200 + transmission (2.94-2) unstable; urgency=medium [ Ondřej Nový ] diff -Nru transmission-2.94/debian/patches/CVE-

Bug#964574: buster-pu: package file-roller/3.30.1-2+deb10u1

2020-07-08 Thread Moritz Muehlenhoff
0.1-2+deb10u1) buster; urgency=medium + + * CVE-2020-11736 (Closes: #956638) + + -- Moritz Muehlenhoff Wed, 08 Jul 2020 20:12:00 +0200 + file-roller (3.30.1-2) unstable; urgency=medium * Restore -Wl,-O1 to our LDFLAGS diff -Nru file-roller-3.30.1/debian/patches/02_CVE-2020-11736.patch file-r

Bug#964482: buster-pu: xen/4.11.4+24-gddaaccbbab-1~deb10u1

2020-07-08 Thread Moritz Muehlenhoff
On Tue, Jul 07, 2020 at 10:56:18PM +0200, Hans van Kranenburg wrote: > Additional To: t...@security.debian.org > > Hi Security team, > > After our last security update, which was > 4.11.3+24-g14b62ab3e5-1~deb10u1, we found out that there is a bugfix to > be done to help users upgrade from Buster

Bug#950693: RM: radare2/1.1.0+dfsg-5

2020-02-04 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Please remove radare2 from Stretch. There's a number of unfixed security issues and upstream actively objects it's presence in a stable release: #950372 Cheers, Moritz

Bug#950692: RM: radare2-cutter/1.7.4-2

2020-02-04 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm See my earlier RM bug for radare2 itself. Cheers, Moritz

Bug#950691: RM: radare2/3.2.1+dfsg-5

2020-02-04 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Please remove radare2 from Buster. There's a number of unfixed security issues and upstream actively objects it's presence in a stable release: #950372 (There's an rdep (radere2-cutter) to be re

Bug#949541: buster-pu: package mesa/18.3.6-2+deb10u1

2020-01-21 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Attached debdiff fixes a minor security issue in mesa. I've been running the updated packaged on a Buster workstation over the last days. Cheers, Moritz diff -u mesa-18.3.6

Bug#948104: buster-pu: package python3.7/3.7.3-2+deb10u1

2020-01-03 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Similar to the python2.7 update which landed in Buster 10.2. Debdiff below. All these are fixed in bullseye/sid (but none had a dedicated bug) Cheers, Moritz diff -Nru pyth

Re: on updating debian-security-support in stable and oldstable (due to DSA-4562-1)

2019-11-28 Thread Moritz Muehlenhoff
On Thu, Nov 28, 2019 at 12:03:25PM +, Holger Levsen wrote: > - for stretch, I will upload to stretch-security and that's it. Sounds good, I'll take care of releasing that. Cheers, Moritz

Re: on updating debian-security-support in stable and oldstable (due to DSA-4562-1)

2019-11-27 Thread Moritz Muehlenhoff
On Wed, Nov 27, 2019 at 09:43:26AM +0100, Salvatore Bonaccorso wrote: > Hi Holger, > > On Tue, Nov 26, 2019 at 01:03:00PM +, Holger Levsen wrote: > > On Sun, Nov 24, 2019 at 08:27:40PM +, Adam D. Barratt wrote: > > > On Sun, 2019-11-24 at 18:42 +, Holger Levsen wrote: > > > > - or shou

Bug#943846: buster-pu: package python-cryptography/2.6.1-3+deb10u2

2019-10-30 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu (This is a followup update on top of the +deb10u1 already in s-p-u, I've reached out to Tristan beforehand) Attached debdiff fixes a memory leak in python-cryptography, which was no

Bug#943364: buster-pu: package python2.7/2.7.16-2+deb10u1

2019-10-23 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu This fixes a number of low severity issues which have popped up since the initial Buster release. Debdiff below. Cheers, Moritz diff -u python2.7-2.7.16/debian/changelog py

Bug#938932: RM: pump/0.8.24-7

2019-08-30 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Same as for #935458 in Buster, please also remove from Stretch. Cheers, Moritz

Bug#935746: buster-pu: package nss/2:3.42.1-1+deb10u1

2019-08-25 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu The NSS update below fixes a few non-severe security issues. I've been running this version with Firefox on Buster (which uses the system copy of NSS unlike Firefox in Stretch) witho

Bug#935596: RM: teeworlds/0.6.5+dfsg-1~deb9u1

2019-08-24 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Please remove teeworlds in the 9.10 point release, it has open security issues, but it's not really worth fixing as the package from Stretch is now incompatible with current game servers. Cheers

Bug#935460: stretch-pu: package sox/14.4.1-5+deb9u2

2019-08-22 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Attached debdiff fixes a number of bugs in sox. These have been in jessie for a while already (Stretch and Jessie have the same base version as the package was unmaintained for a wh

Bug#935458: RM: pump/0.8.24-7.1

2019-08-22 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Hi, please remove pump in the 10.1 point release. It's unmaintained both in Debian and upstream and security-buggy. I've gotten in touch with Red Hat (the former upstream), it was formerly develo

Bug#932175: stretch-pu: package openssh/1:7.4p1-10+deb9u7

2019-07-16 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu This update for OpenSSH fixes a dead lock in AuthorizedKeysCommand (#905226). The fixed package is running fine on a formerly affected Stretch system (https://phabricator.wikimedia

Re: Revert some Go packages in unstable to align with testing/buster

2019-07-04 Thread Moritz Muehlenhoff
On Thu, Jul 04, 2019 at 12:30:24PM +0200, Paul Gevers wrote: > Hi security-team, > > On 08-06-2019 23:45, Thorsten Alteholz wrote: > > Hi everybody, > > > > On Wed, 5 Jun 2019, Paul Gevers wrote: > >> One other problem is that tools are lacking to schedule binNMUs on the > >> right packages in an

Bug#930812: unblock: cargo/0.35.0-2

2019-06-22 Thread Moritz Muehlenhoff
On Sat, Jun 22, 2019 at 07:52:40PM +0200, Paul Gevers wrote: > Hi Ximin, > > On 22-06-2019 11:57, Ximin Luo wrote: > > Paul Gevers: > >> On 21-06-2019 07:38, Ximin Luo wrote: > >>> rustc 1.34.2 was unblocked in bug #930661 but the bug requestor forgot to > >>> file > >>> the corresponding unblock

Bug#930661: unblock: rustc/1.34.2+dfsg1-1

2019-06-17 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock The next Firefox ESR 68 (about to obsolete ESR60 in October) will need rustc 1.34, while buster currently has 1.32. This is against all freeze policies, but OTOH only bumping to 1.34 in th

Bug#929603: unblock: webkit2gtk/2.24.2-1

2019-05-30 Thread Moritz Muehlenhoff
On Thu, May 30, 2019 at 08:42:42AM +0200, Paul Gevers wrote: > Control: tags -1 moreinfo > > Hi Alberto, > > On Sun, 26 May 2019 23:08:03 +0200 Alberto Garcia wrote: > > Please unblock package webkit2gtk > > > > The new upstream stable release contains (among others) fixes > > for these three s

Bug#928185: unblock: openjdk-11/11.0.3+7-4

2019-05-27 Thread Moritz Muehlenhoff
On Mon, May 27, 2019 at 03:46:44PM +0200, Matthias Klose wrote: > Control: tag -1 - moreinfo > > On 02.05.19 10:30, Julien Cristau wrote: > > Control: tag -1 moreinfo > > > > Hi Matthias, > > > > On Mon, Apr 29, 2019 at 06:12:36PM +0200, Matthias Klose wrote: > >> Package: release.debian.org > >

Bug#929596: unblock: firefox-esr/60.7.0esr-1

2019-05-26 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package firefox-esr. It's the latest ESR security release. unblock firefox-esr/60.7.0esr-1 Cheers, Moritz

Re: Bug#928026: security support for golang packages in Buster

2019-05-08 Thread Moritz Muehlenhoff
On Wed, May 08, 2019 at 08:45:30AM +0200, Paul Gevers wrote: > > 2. binNMU without full source upload for security-master. > > > >It's still not possible, and I don't know there's any effort to > >change the dak. > > > >But I want to know how security team handles other static linked

Bug#928051: unblock: chromium/74.0.3729.108-1

2019-04-26 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package chromium. It fixes the recent security issues and we're also following upstream releases in stable. unblock chromium/74.0.3729.108-1 Cheers, Moritz

Bug#927483: unblock: wireshark/2.6.8-1

2019-04-20 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package wireshark. It fixes the recent security issues by updating to the latest 2.6.x (Wireshark in stretch-security also follows upstream releases (as will buster-security)

Bug#927424: stretch-pu: package rails/2:4.2.7.1-1+deb9u1

2019-04-19 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Fixes three issues in rails, debdiff below. Passes all regressions tests and a quick functional test. Cheers, Moritz diff -Nru rails-4.2.7.1/debian/changelog rails-4.2.7.1

Bug#926897: stretch-pu: package audiofile/0.3.6-4+deb9u1

2019-04-11 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Fixes two minor security issue, debdiff below. Cheers, Moritz diff -Nru audiofile-0.3.6/debian/changelog audiofile-0.3.6/debian/changelog --- audiofile-0.3.6/debian/change

Bug#926890: unblock: audiofile/0.3.6-5

2019-04-11 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package audiofile. It fixes two security issues and updates the meta data away from Alioth to Salsa. unblock audiofile/0.3.6-5 Cheers, Moritz diff -Nru audiofile-0.

Bug#926739: stretch-pu: package gpac/0.5.2-426-gc5ad4e4+dfsg5-3+deb9u1

2019-04-09 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Fixes a number of minor issues, same patches are also in unstable for a week. Cheers, Moritz diff -Nru gpac-0.5.2-426-gc5ad4e4+dfsg5/debian/changelog gpac-0.5.2-426-gc5ad

  1   2   3   4   5   6   7   8   >