Control: tags 931126 - moreinfo Control: retitle 931126 unblock: enigmail/2:2.0.12+ds1~deb10u1 On Tue 2019-08-20 21:05:37 +0100, Adam D. Barratt wrote: >> I would love it if someone else wants to step up and help with this. >> I'm currently working on an update to GnuPG for buster, and have not >> had time yet to do the 2.0.12 upload for Buster (either as a security >> or point release). > > Tagging as moreinfo for now, until there's a definite plan and diff > either way. Thanks, Adam. Attached is a debdiff for the update to enigmail 2.0.12 for buster. I've also pushed it to the debian/buster branch on salsa. I've reduced the size of the debdiff by about a third by filtering out the changes to the lang/ directory (in particular, the updates to the russian translation are large), but those changes can be seen in git if you're interested. from debian/changelog: +enigmail (2:2.0.12+ds1-1~deb10u1) buster; urgency=medium + + * upload upstream version to Debian stable + - addresses CVE-2019-12269 (Closes: #929363) + - uses "advanced" version of WKD + - switches to using keys.openpgp.org as the default keyserver + - avoid decrypting/verifying quoted inline-PGP + - un-mangling MS Exchange: ensure that message structure is + as expected to avoid data loss + - only include Subject: line in legacy-display part for + protected headers + * move Vcs-Git fields to DEP-14 branch debian/buster + * refresh patches + + -- Daniel Kahn Gillmor <dkg@fifthhorseman.net> Wed, 21 Aug 2019 12:57:35 -0400 Please let me know if i should go ahead with the upload. Regards, --dkg
Attachment:
enigmail_2:2.0.10+ds1-1_2:2.0.12+ds1-1~deb10u1.debdiff.gz
Description: application/gzip
Attachment:
signature.asc
Description: PGP signature