On Thu, 2021-04-22 at 14:17 +0200, Ivo De Decker wrote: > tags -1 confirmed moreinfo > > On Thu, Apr 22, 2021 at 02:09:20PM +0200, Moritz Mühlenhoff wrote: > > Am Wed, Apr 21, 2021 at 09:31:12AM +0300 schrieb Sebastian Dröge: > > > In addition to various more minor bugs, this release also fixes > > > CVE-2021-3497 > > > and CVE-2021-3498 as well as other potentially security-relevant > > > issues that > > > didn't get their own CVE. > > > > JFTR, there was an earlier discussion about CVE-2021-3497/CVE-2021- > > 3498 with > > Sebastian and given the way gstreamer release branches are handled > > we > > suggested to ask for an unblock of 1.18.4 (it's fundamentally quite > > similar > > to ffmpeg or vlc where we're also following release branches). > > OK, thanks for the clarification. > > You can go ahead with the uploads of these packages, and remove the > moreinfo tag from this bug once they are ready to migrate.
Thanks, I'll upload the new versions this evening. > Please note that it seems there was a fix for #984579 in the upload > to unstable that isn't included in the upload to experimental. I > assume this will be fixed in the next upload as well. Yes, that's already included in my local version.
signature.asc
Description: This is a digitally signed message part