A DSA is needed for the following source packages in old/stable. The specific CVE IDs do not need to be listed, they can be gathered in an up-to-date manner from https://security-tracker.debian.org/tracker/source-package/SOURCEPACKAGE when working on an update. Some packages are not tracked here: - Linux kernel (tracking in kernel-sec repo) - Embargoed issues continue to be tracked in separate file. To pick an issue, simply add your uid behind it. If needed, specify the release by adding a slash after the name of the source package. -- 389-ds-base (fw) -- chromium-browser -- graphicsmagick -- graphite2 -- libytnef -- linux wait until more issues have piled up -- php5 wait until more issues have piled up/next upstream point release -- phpmyadmin -- qemu Maintainer asked to prepare updates -- sudo (carnil) -- tiff wait until more issues have piled up -- vlc Maintainer proposed debdiff, needs review and ack -- wireshark (seb) 2017-05-13: asked balint@ if he wants to prepare an update now --