DLA 2550-1: CVE-2020-27844: Patch present in source but not applied?

2021-03-15 Thread Salvatore Bonaccorso
Hi Brian, LTS team, This was reported by the Ubuntu security team: The DLA 2550-1 update was aiming to fix CVE-2020-27844 as well, but it looks that whilst a patch is included in debian/patches the series files does not apply it. To be on safe side I have removed the listing for CVE-2020-27844 in

(semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2021-03-15 Thread Holger Levsen
hi, today one package was unclaimed for LTS: - php-pear (Ola Lundqvist) and none for ELTS. Noone claimed 4 packages or more. Two DLAs which already had been reserved last week have not yet been published: - DLA 2592-1 (13 Mar 2021) (golang-1.8) - DLA 2591-1 (13 Mar 2021) (golang-1.7) -- chee

RE: [EXTERNAL] Re: Bug#962596: Backport to stretch?

2021-03-15 Thread Damon Tivel
Thanks so much, Utkarsh! Damon -Original Message- From: Utkarsh Gupta Sent: Saturday, March 13, 2021 11:10 AM To: Damon Tivel ; Michael Simons (.NET) Cc: debian-lts@lists.debian.org; 962...@bugs.debian.org; Jon Douglas Subject: [EXTERNAL] Re: Bug#962596: Backport to stretch? Hi Dam