(E)LTS report for October 2023

2023-11-04 Thread Adrian Bunk
LTS: poppler: - Confirmed that CVE-2020-18839 is a duplicate of CVE-2020-27778 - Released DLA-3620-1, fixing CVE-2020-23804 CVE-2022-37050 CVE-2022-37051 - PoCs for all 3 CVEs were confirmed to be present in the unfixed version and fixed in the fixed version krb: - Released DLA-3626-1, fixing

Debian (E)LTS report for October 2023

2023-11-02 Thread Lee Garrett
Hi everyone, In October I published the initial version of ftf (functional test framework) and fixed many things thanks to Santiago's feedback. It is now published at https://gitlab.com/lgarrett/ftf. I also spent time continuing work on samba, triaging the remaining CVEs and preparing an upd

(E)LTS report for October 2023

2023-11-01 Thread Tobias Frost
I've worked during October 2023 on the below listed packages, for Freexian LTS/ELTS [1] Many thanks to Freexian and sponsors [2] for providing this opportunity! ELTS: firmware-nonfree - ELA-981-1 This was a contiunation of DLA-3596-1, which I've released in September, this time for EL