November Report


Here is my LTS report for November.

I was allocated 15 hours. I have spent all of them in the following

* openjpeg2:

  Continue my investigations on CVE-2018-18088, finish patch and get it
  reviewed by upstream (actually merged). Triage CVE-2018-5785 as not
  affecting Jessie (vulnerable code introduced later).

  Prepare a jessie security upload including my work from the previous
  months, test and upload it (DLA 1579-1).

  Investigate CVE-2018-6616 and start developing a patch addressing this
  issue. See upstream bug report.

* liblivemedia:

  Prepare, test and upload security update addressing CVE-2018-4013
  (DLA 1582-1). Upload was also done for Stretch.

* libtiff:

  Investigate CVE-2018-19210, prepare a patch addressing this issue.
  Still waiting for review from upstream, see

* libsndfile:

  Take a look at the state of older CVEs, looks like some of them triaged
  no-dsa might be worth an upload. Assess their reproducibility, add to
  dla-needed and start preparing upload.

* misc:

  + test and review Santiago's QEMU upload.

