Bug#773416: fixed in ettercap 1:0.8.1-3

2014-12-23 Thread Gianfranco Costamagna
Mentor rejected it "Hello, Unfortunately your package "ettercap" was rejected because of the following reason: You are not uploading to one of those Debian distributions: experimental jessie jessie-backports jessie-backports-sloppy jessie-security jessie-updates oldstable oldstable-backports o

Bug#773416: fixed in ettercap 1:0.8.1-3

2014-12-23 Thread Gianfranco Costamagna
Hi Raphael, >The target serie is "squeeze-lts". You can upload the .dsc to mentors if >you want (or just send the debdiff as attachment here). >It was copy/pasted in email and lost spaces so it's best if you can resend >it as proper attachment. >Don't worry about this, if you have source package

Bug#773416: fixed in ettercap 1:0.8.1-3

2014-12-23 Thread Raphael Hertzog
Hi Gianfranco, On Tue, 23 Dec 2014, Gianfranco Costamagna wrote: > the patch is already above, I didn't tweak the changelog because I don't > even know the best target series, and I don't know where to > patch/prepare the upload. The target serie is "squeeze-lts". You can upload the .dsc to mento

Bug#773416: fixed in ettercap 1:0.8.1-3

2014-12-23 Thread Gianfranco Costamagna
Hi Barak and Raphael, the patch is already above, I didn't tweak the changelog because I don't even know the best target series, and I don't know where to patch/prepare the upload. Is that "debdiff" sufficient or not? I can create a squeeze chroot and prepare a build, if it is enough the abov

Bug#773416: fixed in ettercap 1:0.8.1-3

2014-12-22 Thread Barak A. Pearlmutter
> Thanks for the prompt reaction. My pleasure. > ettercap is also in Squeeze and thus covered by our LTS initiative. > Do you feel like providing a fixed package for Squeeze? > If yes, please have a look at http://wiki.debian.org/LTS/Development > but note that if you provide the fixed package

Bug#773416: fixed in ettercap 1:0.8.1-3

2014-12-22 Thread Gianfranco Costamagna
Hi Raphael, >Thanks for the info! So the only remaining CVE would be >https://security-tracker.debian.org/tracker/CVE-2014-9380 and >https://security-tracker.debian.org/tracker/CVE-2014-9381 for the CVS >dissector. yes, I think yes. >BTW, https://security-tracker.debian.org/tracker/CVE-2014-937

Bug#773416: fixed in ettercap 1:0.8.1-3

2014-12-22 Thread Raphael Hertzog
On Mon, 22 Dec 2014, Gianfranco Costamagna wrote: > Hi dear Raphael, > > fortunately oldstable is almost unaffected by this kind of CVEs, because > almost all of them > refers to code written after the squeeze release, anyway here we go, this > should be the only > patch useful for squeeze folks

Bug#773416: fixed in ettercap 1:0.8.1-3

2014-12-22 Thread Gianfranco Costamagna
Hi dear Raphael, fortunately oldstable is almost unaffected by this kind of CVEs, because almost all of them refers to code written after the squeeze release, anyway here we go, this should be the only patch useful for squeeze folks --- ettercap-0.7.3.orig/src/dissectors/ec_cvs.c +++ ettercap-

Bug#773416: fixed in ettercap 1:0.8.1-3

2014-12-22 Thread Raphael Hertzog
Hello Barak, On Thu, 18 Dec 2014, Barak A. Pearlmutter wrote: > ettercap (1:0.8.1-3) unstable; urgency=high > . >* Patch a bunch of security vulnerabilities (closes: #773416) Thanks for the prompt reaction. ettercap is also in Squeeze and thus covered by our LTS initiative. Do you feel lik