[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Jessie update of cron?

Hi Mike,

On 2019-03-15 14:52, Mike Gabriel wrote:
> Dear maintainer(s),
> The Debian LTS team would like to fix the security issues which are
> currently open in the Jessie version of cron:
> https://security-tracker.debian.org/tracker/CVE-2019-9704
> https://security-tracker.debian.org/tracker/CVE-2019-9705
> https://security-tracker.debian.org/tracker/CVE-2019-9706
> https://security-tracker.debian.org/tracker/CVE-2017-9525
> For Debian stretch, these issues have been marked as <no-dsa>. However,
> for Debian LTS, we would like to get those issues resolved.
> Would you like to take care of this yourself?

I had planned to prepare fixes for jessie and stretch, but in
discussion with the security team, it was considered to wait
until these fixes migrate to buster before we fix stable and

If you'd rather not wait, I can prepare fixes earlier, but not
before Sunday -- I should probably make Tuesday.

> If yes, please follow the workflow we have defined here:
> https://wiki.debian.org/LTS/Development
> If that workflow is a burden to you, feel free to just prepare an
> updated source package and send it to debian-lts@lists.debian.org
> (via a debdiff, or with an URL pointing to the source package,
> or even with a pointer to your packaging repository), and the members
> of the LTS team will take care of the rest. Indicate clearly whether you
> have tested the updated package or not.
> If you don't want to take care of this update, it's not a problem, we
> will do our best with your package. Just let us know whether you would
> like to review and/or test the updated package before it gets released.
> You can also opt-out from receiving future similar emails in your
> answer and then the LTS Team will take care of cron updates
> for the LTS releases.
> Thank you very much.
> Mike Gabriel,
>   on behalf of the Debian LTS team.
> PS: A member of the LTS team might start working on this update at
> any point in time. You can verify whether someone is registered
> on this update in this file:
> https://salsa.debian.org/security-tracker-team/security-tracker/raw/master/data/dla-needed.txt

Good to know, thanks!


Reply to: