DSA candidates

2016-02-29 Thread Raphael Geissert
activemq -- bsh -- cakephp -- coreutils -- dhcpcd5 -- gdm3 -- glance -- gosa -- graphicsmagick -- gtk+2.0 -- icinga -- icu -- imlib2 -- inspircd -- libebml -- libmatroska -- libspring-java -- libtorrent-rasterbar -- libuser -- libvpx -- libxml2 -- mono -- nova -- openssl -- php5 -- phpmyadmin -- po

refresh, backports in security-tracker

2016-02-29 Thread Geert Stappers
FWIW updating the ticket - Forwarded message from Salvatore Bonaccorso - Date: Mon, 29 Feb 2016 21:05:02 +0100 From: Salvatore Bonaccorso To: Geert Stappers Cc: debian-security-tracker@lists.debian.org Subject: Re: severity-tracker and backports Hi Geert, On Mon, Feb 29, 2016 at 08:5

Re: severity-tracker and backports

2016-02-29 Thread Salvatore Bonaccorso
Hi Geert, On Mon, Feb 29, 2016 at 08:58:00PM +0100, Geert Stappers wrote: > Hi, > > https://security-tracker.debian.org/tracker/CVE-2016-1898 > mentions wheezy and stretch, but not jessie, neither jessie-backports. > > CVE-2016-1898 is about a ffmpeg vulnerbility. > > ffmpeg is not in jessie, b

severity-tracker and backports

2016-02-29 Thread Geert Stappers
Hi, https://security-tracker.debian.org/tracker/CVE-2016-1898 mentions wheezy and stretch, but not jessie, neither jessie-backports. CVE-2016-1898 is about a ffmpeg vulnerbility. ffmpeg is not in jessie, but it is in jessie-backports. The CVE-2016-1898 vulnerbility is is fixed in jessie-backpor