Bug#796108: CVE-2015-5694 CVE-2015-5695

2015-08-19 Thread Kiall Mac Innes
, Kiall Mac Innes wrote: Hey - Upstream Designate maintainer here. Icehouse - aka 2014.1 - is partially affected by CVE-2015-5695, failure to enforce recordset quotas. This was the less severe of the two CVEs, which we treated as a feature not implemented rather than a security issue initially

Bug#796108: CVE-2015-5694 CVE-2015-5695

2015-08-19 Thread Kiall Mac Innes
Hey - Upstream Designate maintainer here. Icehouse - aka 2014.1 - is partially affected by CVE-2015-5695, failure to enforce recordset quotas. This was the less severe of the two CVEs, which we treated as a feature not implemented rather than a security issue initially. Additionally, the iss

Bug#668441: Bug #668441

2012-04-12 Thread Kiall Mac Innes
ew as the > main repo? Could be that an alternative? > > Ghe Rivero > > On Thu, Apr 12, 2012 at 12:21 AM, Kiall Mac Innes wrote: > >> I had thought Chuck had removed those URLs before uploading to Ubuntu - >> (And I didn't know it had made it up into Debian..)..

Bug#668441: Bug #668441

2012-04-11 Thread Kiall Mac Innes
I had thought Chuck had removed those URLs before uploading to Ubuntu - (And I didn't know it had made it up into Debian..).. Anyway - I've opened anon access to the repo, although the Vcs-Browser URL will still 404 unless you are signed in due to a Gerrit bug. Please feel free to leave them, rem

Bug#657698: [PHP-DEV] Suhosin patch disabled by default in Debian php5 builds

2012-02-04 Thread Kiall Mac Innes
Hi John, Ondřej (One of the Debian PHP maintainers) listed 5 or 6 reasons in the initial email in this thread. Honestly, I can't think of a good reason for Debian or anyone else to include 3rd party patches, whatever the patches purpose, in the default PHP packages. I would argue that, if peopl