A DSA is needed for the following source packages in old/stable. The specific CVE IDs do not need to be listed, they can be gathered in an up-to-date manner from https://security-tracker.debian.org/tracker/source-package/SOURCEPACKAGE when working on an update. Some packages are not tracked here: - Linux kernel (tracking in kernel-sec repo) - Embargoed issues continue to be tracked in separate file. To pick an issue, simply add your uid behind it. If needed, specify the release by adding a slash after the name of the source package. -- 389-ds-base (fw) -- asterisk -- chromium-browser/stable -- gimp (carnil) -- graphicsmagick -- imagemagick/oldstable (jmm) -- libav/oldstable We can ship the next libav 11.x point release when available -- libidn -- libvpx/oldstable -- libxml2 (carnil) -- linux Wait until more issues have piled up -- openjpeg2 -- passenger/stable -- php-horde-image -- php5 -- php7.0 -- phpmyadmin/oldstable -- pjproject -- poppler (jmm) 2017-11-23: santiago will prepare a debdiff 2017-12-02: santiago prepared debdiffs available for review -- qemu/oldstable -- redmine oldstable also affected, but might be worth EOLing -- ruby2.1/oldstable -- salt -- simplesamlphp -- sqlite3/oldstable -- sssd/stable -- thunderbird -- tomcat7/oldstable -- tomcat8 -- tiff wait until more issues are around -- wordpress -- xen -- zendframework/oldstable --