Bug#933637: Bug#933636: CVE-2019-14934
- To: 933637@bugs.debian.org
- Cc: Francois Marier <francois@debian.org>
- Subject: Bug#933637: Bug#933636: CVE-2019-14934
- From: Salvatore Bonaccorso <carnil@debian.org>
- Date: Fri, 26 Mar 2021 07:27:27 +0100
- Message-id: <YF1+z0kaTa/ZB9xC@eldamar.lan>
- Reply-to: Salvatore Bonaccorso <carnil@debian.org>, 933637@bugs.debian.org
- In-reply-to: <20200731081823.GA574119@eldamar.local>
- References: <20190801085401.GA23159@akranes.dyn.fmarier.org> <20190814062955.GD29207@akranes.dyn.fmarier.org> <20190801085401.GA23159@akranes.dyn.fmarier.org> <d8b96b85c7c39f7db5a8bcd91e3660b1b3eae46d.camel@adam-barratt.org.uk> <20200207091424.GA1690332@eldamar.local> <20190801085507.GA23386@akranes.dyn.fmarier.org> <20200210235922.GA1979781@akranes.dyn.fmarier.org> <20190801085507.GA23386@akranes.dyn.fmarier.org> <20200731081823.GA574119@eldamar.local> <20190801085507.GA23386@akranes.dyn.fmarier.org>
Hi Francois,
On Fri, Jul 31, 2020 at 10:18:23AM +0200, Salvatore Bonaccorso wrote:
> Hi Francois,
>
> On Mon, Feb 10, 2020 at 03:59:22PM -0800, Francois Marier wrote:
> > On 2020-02-07 at 10:14:24, Salvatore Bonaccorso wrote:
> > > > It looks OK to me. Tagging moreinfo until there's a final diff.
> > >
> > > Friendly ping, any news? (It's too late now for the upcoming point
> > > release though).
> >
> > It's still on my list, but not a very high priority. Definitely won't happen
> > until at least after the Ubuntu 20.04 Debian merge deadline.
>
> It would now be too late for the 10.5 buster point release, but do you
> found time to finalize the debdiff for review for SRM? Then we might
> target for 10.6.
There are in meanwhile one more CVE which might be included. They are
at this time CVE-2019-14267, CVE-2020-9549, CVE-2019-14934 and
CVE-2020-20740 which are all marked no-dsa or unimportant (with
negligible security impact), but maybe if you still would like to fix
those for buster, we can close this report and then open a new one
with a revisited debdiff?
What do you think?
Regards,
Salvatore
Reply to: