[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

bson CVEs in (E)LTS



Hi,

mongo-c-driver was added to *la-needed.txt yesterday, and someone 
already claimed it to fix the 4 bson CVEs (and a non-bson CVE) in 
bullseye and buster.

Copies of the bson code are also in the (E)LTS supported packages 
libbson/stretch and libbson-xs-perl/bullseye.

Front Desk / Security Team:
CVEs need syncing between these 3 source packages.

It would make sense if the same person fixes the CVEs in all copies of 
the bson code in all releases.

cu
Adrian


Reply to: