Call for testers: Freeradius updates that mitigate Blast-RADIUS

2024-08-26 Thread Santiago Ruano Rincón
Dear Debian LTS users, Bernhard (FreeRADIUS debian maintainer), Bastien and myself (with the kind help from Alan DeKok - upstream maintainer) have been preparing freeradius updates that mitigate the Blast-RADIUS issue for both bookworm and bullseye. To mitigate the vulnerability, RADIUS servers a

Re: [SECURITY] [DLA 3856-1] python-html-sanitizer security update

2024-08-26 Thread Ben Hutchings
On Mon, 2024-08-26 at 16:55 +0100, Chris Lamb wrote: > - > Debian LTS Advisory DLA-3856-1debian-lts@lists.debian.org > https://www.debian.org/lts/security/ Chris Lamb > August 26, 2024

Re: [SECURITY] [DLA 3856-1] python-html-sanitizer security update

2024-08-26 Thread Chris Lamb
Ben Hutchings wrote: > This version is not yet available, presumably because there is still a > policy queue for bullseye-security. > > Please check that an uploaded package has actually been built and > released before issuing the corresponding DLA. Eek. I assumed it had been built successfully

The bullseye-security upload queue is still closed (was: [SECURITY] [DLA 3856-1] python-html-sanitizer security update)

2024-08-26 Thread Santiago Ruano Rincón
El 26/08/24 a las 19:22, Adrian Bunk escribió: > Hi, > > where has the binary package been built, and where is it available for > our users to download? > > Except for this announcement, I have not seen traces of it anywhere. python-html-sanitizer and libtommath uploads have been rejected. Chri

Re: [SECURITY] [DLA 3856-1] python-html-sanitizer security update

2024-08-26 Thread Adrian Bunk
Hi, where has the binary package been built, and where is it available for our users to download? Except for this announcement, I have not seen traces of it anywhere. cu Adrian On Mon, Aug 26, 2024 at 04:55:35PM +0100, Chris Lamb wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > >

Re: Bug#1079502: youtube-dl: GHSA-22fp-mf44-f2mq GHSA-9jqj-9wwh-r5mg

2024-08-26 Thread Santiago Ruano Rincón
Control: severity -1 important (CCing: the security team) Hi, El 24/08/24 a las 02:08, alexvong.rc...@simplelogin.com escribió: > Subject: youtube-dl: GHSA-22fp-mf44-f2mq GHSA-9jqj-9wwh-r5mg > Source: youtube-dl > Version: 2021.12.17-1~bpo11+1 > X-Debbugs-Cc: debian-lts@lists.debian.org > Severi

wb: bullseye-security still configured for all architectures?

2024-08-26 Thread Adrian Bunk
Hi, looking at [1], bullseye-security still lists all architectures for bullseye-security. Intended[2] is the same architecture list as was for buster-security (all amd64 arm64 armhf i386). cu Adrian [1] https://buildd.debian.org/ [2] https://wiki.debian.org/LTS