Re: Bugs introduced by source uploads

2020-10-13 Thread Holger Levsen
On Fri, Oct 09, 2020 at 09:37:03AM +0200, Sylvain Beucler wrote: [...] > It is particularly difficult to catch, because it can only be detected > after the security upload, while our testing (obviously) happens before. > > To help detect this ahead of time, I modified and tested the recommended >

Bug#972189: sympa: CVE-2020-10936 regression - removal of needed environment variables

2020-10-13 Thread Carsten Aulbert
Package: sympa Version: 6.2.16~dfsg-3+deb9u3 Severity: important Dear Maintainer(s), since applying the security update from 6.2.16~dfsg-3+deb9u2 to 6.2.16~dfsg-3+deb9u3 I found some troubles with the session handling, i.e. the web server reports 2020/10/13 11:59:18 [error] 2123#2123: *3525 Fast