Re: curl: CVE-2023-28322 and CVE-2023-27534

2023-12-18 Thread Adrian Bunk
On Sat, Dec 16, 2023 at 10:39:08PM -0300, Samuel Henrique wrote: >... > On Thu, 30 Nov 2023 at 06:36, Markus Koschany wrote: > > I have recently triaged CVE-2023-28322 and CVE-2023-27534 for curl as > > ignored > > for Buster because I believe those are minor issues. Since you expressed > > inter

curl: CVE-2023-28322 and CVE-2023-27534

2023-12-18 Thread Samuel Henrique
Hello Adrian, On Mon, 18 Dec 2023 at 10:22, Adrian Bunk wrote: > For releases where it has been backported, I've added a link to a > regression fix in the security tracker.[1] Thank you, I remember seeing the regression fix somewhere and I forgot to apply the fix. > Regarding LTS, CVE-2023-4621