Re: bson CVEs in (E)LTS
On Mon, Mar 31, 2025 at 04:20:08PM +0100, Chris Lamb wrote:
> Adrian Bunk wrote:
>
> > It would make sense if the same person fixes the CVEs in all copies of
> > the bson code in all releases.
>
> Indeed it would. If someone has a connection or history with any of
> these packages already, I'd be more than happy to relinquish my claim
> on mongo-c-driver so they are all handled together.
>
Thanks! I've taken them over just now.
> (At the time of writing they are not yet in {dla,ela}-needed.txt AFAICS.)
>
Whenever the rest show up, I'll grab them as well.
Regards,
-Roberto
--
Roberto C. Sánchez
Reply to: