Bug#1093043: dcmtk: leftover CVE status.

2025-02-13 Thread Étienne Mollier
Good day, Salvatore Bonaccorso, on 2025-02-12: > Thanks a lot for your work, and for providing this status update. Then > I suggest that we do not not ignore the remaining CVEs and you can > address this equally trough the point release. Sounds good, I opened #1095072 to discuss the integration.

Bug#1093043: dcmtk: leftover CVE status.

2025-02-09 Thread Salvatore Bonaccorso
Hi Étienne On Sun, Feb 02, 2025 at 11:46:44AM +0100, Étienne Mollier wrote: > Good day, > > Étienne Mollier, on 2025-02-01: > > I believe these changes in dcmtk are good enough to contact the > > stable release manager for an upload in the upcoming point > > release and will proceed. > > And don

Bug#1093043: dcmtk: leftover CVE status.

2025-02-02 Thread Étienne Mollier
Good day, Étienne Mollier, on 2025-02-01: > I believe these changes in dcmtk are good enough to contact the > stable release manager for an upload in the upcoming point > release and will proceed. And done, this is #1094991. Have a nice day, :) -- .''`. Étienne Mollier : :' : pgp: 8f91 b

Bug#1093043: dcmtk: leftover CVE status.

2025-02-01 Thread Étienne Mollier
Hello, I tried to have a closer look at CVE-2024-28130 in dcmtk in bookworm and noted there were ports of fixes to Debian bullseye LTS earlier that year. Either by picking upstream commits or by fetching LTS patches, changes were sufficiently involved that I didn't feel confident to make the nece