(E)LTS report for August 2024

2024-09-10 Thread Adrian Bunk
LTS: amanda: - Released DLA-3880-1, fixing CVE-2022-37703, CVE-2022-37704, CVE-2022-37705 and CVE-2023-30577. aom: - Released DLA-3881-1, fixing CVE-2024-5171. bluez: - Released DLA-3879-1, fixing CVE-2021-3658, CVE-2021-41229, CVE-2021-43400, CVE-2022-0204, CVE-2022-39176, CVE-2022-39177,

(E)LTS report for August 2024

2024-09-03 Thread Tobias Frost
I've worked during August 2024 on the below listed packages, for Freexian LTS/ELTS [1] Many thanks to Freexian and sponsors [2] for providing this opportunity! frr (DLA-3865-1) I've previously uploaded frr for buster; this is bascially a revisit of a previous upload, DLA-3797-1,

Debian (E)LTS report for August 2024

2024-09-01 Thread Guilhem Moulin
During the month of August 2024 and on behalf of Freexian, I worked on the following: roundcube - Uploaded 1.3.17+dfsg.1-1~deb10u7 to buster-security resp. 1.4.15+dfsg.1-1+deb11u4 to bullseye-security, and issued ELA-1170-1 for * CVE-2024-42008: XSS in serving of attachments other than