[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [buster] CVE-2022-46871: libusrsctp maybe backporting a new version ?



On Mon, 2023-06-19 at 11:02 +0000, roucaries bastien wrote:
> Le dim. 18 juin 2023 à 19:16, Ola Lundqvist <ola@inguza.com> a écrit :
> [adding security team]
[...]
> 
> > You mention rebuild all reverse dependencies. Well I do not find any
> > within Debian.
> > This makes it even less important to fix it.
> 
> Yes, but for firefox it is embeded (code duplication not nice). May be
> (so copy security team) deemded it and link to the lib. Less work

So we can expect Firefox upstream to update their copy.

> > ola@buster-lts:~/build$ apt-rdepends -r libusrsctp1
> > Reading package lists... Done
> > Building dependency tree
> > Reading state information... Done
> > libusrsctp1
> >   Reverse Depends: libusrsctp-dev (= 0.9.3.0+20190127-2)
> >   Reverse Depends: libusrsctp-examples (= 0.9.3.0+20190127-2)
> > libusrsctp-dev
> > libusrsctp-examples
> > ola@buster-lts:~/build$ apt-rdepends -r libusrsctp-dev
> > Reading package lists... Done
> > Building dependency tree
> > Reading state information... Done
> > libusrsctp-dev
> 
> No it is incomplete:
> grep-dctrl -FBuild-Depends libusrsctp-dev -w -sPackage
> /var/lib/apt/lists/*Sources
> give me:
> - janus on o-o-stable-backport
> 
> Do not know what to do with it.

buster-backports is not supported at all, so we don't need to care
about that.

I think we can mark this package us unsupported.

Ben.

-- 
Ben Hutchings
Experience is directly proportional to the value of equipment destroyed
                                                    - Carolyn Scheppner

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: