Bug#641405: several Django security issues

2011-10-28 Thread Thijs Kinkhorst
On Fri, 28 Oct 2011 09:15:22 +0200, Raphael Hertzog wrote: > Since you insist, I looked into it and backporting the patches was a > reasonable amount of work... I uploaded > python-django_1.0.2-1+lenny3_i386.changes to oldstable-security and also > here: > http://people.debian.org/~hertzog/packag

Bug#641405: several Django security issues

2011-10-28 Thread Raphael Hertzog
Hi, On Thu, 27 Oct 2011, Thijs Kinkhorst wrote: > > What about a: "There is no Lenny security fix at the moment. If you use > > Lenny and upgrading to Squeeze is really a problem, please drop a mail > > at the security mailinglist. Making this fix is a lot of work, we will > > only do it when ther

Bug#641405: several Django security issues

2011-10-27 Thread Paul van der Vlis
Op 27-10-11 21:40, Thijs Kinkhorst schreef: > > On Thu, 27 Oct 2011 19:43:14 +0200, Paul van der Vlis > wrote: >> Hello, >> >> How is it with this bug? I did not see a security update in Squeeze. > > We still need a fix for Lenny indeed. > >> I understand there is a diskussion about a fix for L

Bug#641405: several Django security issues

2011-10-27 Thread Thijs Kinkhorst
On Thu, 27 Oct 2011 19:43:14 +0200, Paul van der Vlis wrote: > Hello, > > How is it with this bug? I did not see a security update in Squeeze. We still need a fix for Lenny indeed. > I understand there is a diskussion about a fix for Lenny, but Squeeze is > more important in my opinion. I thin

Bug#641405: several Django security issues

2011-10-27 Thread Raphael Hertzog
On Thu, 27 Oct 2011, Paul van der Vlis wrote: > How is it with this bug? I did not see a security update in Squeeze. I did upload my updated package to the security archive after Thijs confirmed it being good but I haven't heard back since then. Cheers, -- Raphaël Hertzog ◈ Debian Developer Pre

Bug#641405: several Django security issues

2011-10-27 Thread Paul van der Vlis
Hello, How is it with this bug? I did not see a security update in Squeeze. I understand there is a diskussion about a fix for Lenny, but Squeeze is more important in my opinion. I think Django in Lenny is not much used anymore. What about a: "There is no Lenny security fix at the moment. If you

Bug#641405: several Django security issues

2011-10-11 Thread Thijs Kinkhorst
Hi Raphaël, Op vrijdag 7 oktober 2011 10:41:26 schreef Thijs Kinkhorst: > > > > > > I have prepared the Squeeze update. I have no way to test it since I > > don't run any website with Django on top of Squeeze currently but I > > don't see any reason why it shouldn't work. The extensive test suite

Bug#641405: several Django security issues

2011-10-07 Thread Thijs Kinkhorst
Hi Raphaël, Op donderdag 6 oktober 2011 14:19:40 schreef Raphael Hertzog: > On Mon, 03 Oct 2011, Thijs Kinkhorst wrote: > > Is work in progress on updates for squeeze and lenny of Django for these > > issues? > > I have prepared the Squeeze update. I have no way to test it since I don't > run any

Bug#641405: several Django security issues

2011-10-06 Thread Raphael Hertzog
On Mon, 03 Oct 2011, Thijs Kinkhorst wrote: > Is work in progress on updates for squeeze and lenny of Django for these > issues? I have prepared the Squeeze update. I have no way to test it since I don't run any website with Django on top of Squeeze currently but I don't see any reason why it shou

Bug#641405: several Django security issues

2011-10-03 Thread Thijs Kinkhorst
Hi all, On Mon, 19 Sep 2011 03:43:14 -0500, James Bennett wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Raphael Hertzog wrote: >> The last 2 release (besides the current one) are security maintained, >> aka 1.1 and 1.2. Since 1.1 has not seen any update, it means it's not >> affe

Bug#641405: several Django security issues

2011-09-19 Thread James Bennett
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Raphael Hertzog wrote: > The last 2 release (besides the current one) are security maintained, > aka 1.1 and 1.2. Since 1.1 has not seen any update, it means it's not > affected and thus 1.0 isn't as well. > > But we can verify this. I'm ccing James B

Bug#641405: several Django security issues

2011-09-19 Thread Raphael Hertzog
On Mon, 19 Sep 2011, Thijs Kinkhorst wrote: > > I'll let you handle the stable upload. If you can't, please tell us. > > Indeed... > > > Thijs, can you update the security tracker to mark oldstable as not > > vulnerable ? It has 1.0 and only versions >= 1.2 are vulnerable > > apparently. > > Wha

Bug#641405: several Django security issues

2011-09-19 Thread Thijs Kinkhorst
Op donderdag 15 september 2011 14:57:42 schreef Raphael Hertzog: > On Tue, 13 Sep 2011, Chris Lamb wrote: > > Raphael Hertzog wrote: > > > > > > > Chris, will you take care of the uploads or do you need help? > > > > > > > > Should manage to do it this evening. > > Since you missed your target,

Bug#641405: several Django security issues

2011-09-15 Thread Raphael Hertzog
Hi Chris, On Tue, 13 Sep 2011, Chris Lamb wrote: > Raphael Hertzog wrote: > > > Chris, will you take care of the uploads or do you need help? > > Should manage to do it this evening. Since you missed your target, I took the liberty to prepare the unstable upload (there was more work to do than

Bug#641405: several Django security issues

2011-09-13 Thread Chris Lamb
Raphael Hertzog wrote: > Chris, will you take care of the uploads or do you need help? Should manage to do it this evening. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org `- -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org

Bug#641405: several Django security issues

2011-09-13 Thread Raphael Hertzog
Hi, On Tue, 13 Sep 2011, Thijs Kinkhorst wrote: > Several security issues were announced in Django: > https://www.djangoproject.com/weblog/2011/sep/09/security-releases-issued/ > and a regression fix was later posted: > https://www.djangoproject.com/weblog/2011/sep/10/127/ > > Can you please ensu

Bug#641405: several Django security issues

2011-09-13 Thread Thijs Kinkhorst
Package: python-django Severity: serious Tags: security Hi, Several security issues were announced in Django: https://www.djangoproject.com/weblog/2011/sep/09/security-releases-issued/ and a regression fix was later posted: https://www.djangoproject.com/weblog/2011/sep/10/127/ Can you please ens