Re: Bug#1076596: bookworm-pu: package gtk+2.0/2.24.33-2+deb12u1

2024-07-19 Thread Cyril Brulebois
Simon McVittie (2024-07-19): > Sorry, I should have remembered that because GTK 2 is used in the > graphical installer, this update will require a d-i ack. (Full text > and diff quoted below.) Please go ahead, I'll double check once it lands in pu. In the very worst case, we could dodge at the v

Re: Bug#1076596: bookworm-pu: package gtk+2.0/2.24.33-2+deb12u1

2024-07-19 Thread Simon McVittie
Control: tags -1 + d-i On Fri, 19 Jul 2024 at 12:29:05 +0100, Simon McVittie wrote: > [ Reason ] > CVE-2024-6655. The security team has indicated that they do not intend > to release a DSA for this vulnerability. > > [ Impact ] > If not fixed, GTK 2 apps will load modules specified in $GTK_MODULE