Publishing advisories for regression updates on the website

2019-10-15 Thread Hugo Lefeuvre
Hi, it looks like we don't publish advisories for regression updates on the website (and neither does the security team). We have discussed this on IRC yesterday and it seemed consensual that doing it would be a good idea. parse-dla.pl handles regression updates correctly, so we only need to stat

Re: Publishing advisories for regression updates on the website

2019-10-15 Thread Holger Levsen
Hi Hugo, thanks for bringing this up! On Tue, Oct 15, 2019 at 02:47:56PM +0200, Hugo Lefeuvre wrote: > it looks like we don't publish advisories for regression updates on the > website (and neither does the security team). I believe this is being tracked as #922246 "www/lts: if DLA-1234-1 and D

Backports for CVE-2019-14287 for sudo (was: Re: Ubuntu ESM access)

2019-10-15 Thread Salvatore Bonaccorso
Hi Sylvain, On Tue, Oct 15, 2019 at 12:24:20AM +0200, Sylvain Beucler wrote: > Hi, > > I would like to study Ubuntu's backports of CVE-2012-2337/sudo (since > the stable branch of sudo experienced massive changes since our > versions), but sadly those are not available to the public: > https://us

Re: poppler / CVE-2019-9959

2019-10-15 Thread Brian May
Brian May writes: > It appears if I can work out how to define SPLASH_CMYK for the build, > then I can fix CVE-2019-10871 too. So I will investigate this > possibility. Updated patch. diff -Nru poppler-0.26.5/debian/changelog poppler-0.26.5/debian/changelog --- poppler-0.26.5/debian/changelog