Re: Bug#1068412: apache2: CVE-2024-27316 CVE-2024-24795 CVE-2023-38709

2024-04-22 Thread Yadd
Le 19 avril 2024 08:27:51 GMT+04:00, Yadd a écrit : >On 4/18/24 22:26, Markus Koschany wrote: >> Hi, >> >> Am Donnerstag, dem 18.04.2024 um 12:15 +0400 schrieb Yadd: >>> >>>   - update Buster/apache2 to 2.4.59-1~deb10u1. I prepared a branch: >>

Re: Bug#1068412: apache2: CVE-2024-27316 CVE-2024-24795 CVE-2023-38709

2024-04-18 Thread Yadd
On 4/18/24 22:26, Markus Koschany wrote: Hi, Am Donnerstag, dem 18.04.2024 um 12:15 +0400 schrieb Yadd:   - update Buster/apache2 to 2.4.59-1~deb10u1. I prepared a branch:     buster-security-follow-upstream (to be tested) I believe this is the safest and best way to address those

Re: Bug#1068412: apache2: CVE-2024-27316 CVE-2024-24795 CVE-2023-38709

2024-04-18 Thread Yadd
On 4/17/24 21:14, Moritz Mühlenhoff wrote: [...] DSA has been released, thanks! Cheers, Moritz Hi, The apache2 package in Bullseye and Bookworm follows the upstream releases because it's a mess to extract security fixes from their repository and because Apache/httpd is in practice

Re: Bug#1068412: apache2: CVE-2024-27316 CVE-2024-24795 CVE-2023-38709

2024-04-18 Thread Yadd
On 4/17/24 21:14, Moritz Mühlenhoff wrote: [...] DSA has been released, thanks! Cheers, Moritz Hi, The apache2 package in Bullseye and Bookworm follows the upstream releases because it's a mess to extract security fixes from their repository and because Apache/httpd is in practice

Re: Accepted node-babel 6.26.0+dfsg-3+deb10u1 (source all) into oldoldstable

2023-10-19 Thread Yadd
Hi, I think I did what is needed (mail + webml). Let me know if everything is OK. Regards, Yadd On 10/19/23 02:26, Santiago Ruano Rincón wrote: Hey, node-babel was accepted into buster-security. Yadd, will you do the paperwork by yourself or do you want some help? Cheers, -- S El 18

Re: Bug#1053880: node-babel7: CVE-2023-45133

2023-10-13 Thread Yadd
On 10/13/23 21:41, Santiago Ruano Rincón wrote: Hi Yadd, El 13/10/23 a las 20:59, Yadd escribió: and Buster ;-) Thanks for preparing the fix! Just to be on the safe side, have you been able to test it, and how? I was able to test this patch for Bookworm and Bullseye. For Buster, the best

Re: Bug#1053880: node-babel7: CVE-2023-45133

2023-10-13 Thread Yadd
and Buster ;-) On 10/13/23 18:30, Yadd wrote: Now both bookworm and bullseye On 10/13/23 18:05, Yadd wrote: With the good dist, sorry On 10/13/23 18:04, Yadd wrote: Hi, patch applied successfully, ready to upload. On 10/13/23 17:24, Moritz Mühlenhoff wrote: Source: node-babel7 X-Debbugs

Re: RFC: php-cas (CVE-2022-39369)

2023-06-28 Thread Yadd
to bullseye and will coordinate the uploads with the security team Does Yadd answered ? Bastien Hi, (Adding yadd as suggested on IRC, solicating yadd's input as well) Some updates on php-cas: I've continued to work on php-cas to better assess the situation: I've also received informa

Re: Bug#1021648: buster-pu: package node-xmldom/0.1.27+ds-1+deb10u1

2022-10-18 Thread Yadd
On 18/10/2022 13:10, Emilio Pozuelo Monfort wrote: On 18/10/2022 10:23, Yadd wrote: On 18/10/2022 09:28, Emilio Pozuelo Monfort wrote: Hi Yadd, On 12/10/2022 18:38, Salvatore Bonaccorso wrote: +node-xmldom (0.1.27+ds-1+deb10u1) buster; urgency=medium + +  * Team upload +  * Fix prototype

Re: Bug#1021648: buster-pu: package node-xmldom/0.1.27+ds-1+deb10u1

2022-10-18 Thread Yadd
On 18/10/2022 09:28, Emilio Pozuelo Monfort wrote: Hi Yadd, On 12/10/2022 18:38, Salvatore Bonaccorso wrote: +node-xmldom (0.1.27+ds-1+deb10u1) buster; urgency=medium + +  * Team upload +  * Fix prototype pollution (Closes: #1021618, CVE-2022-37616) + + -- Yadd   Wed, 12 Oct 2022 10:07:56