Debian LTS & ELTS report -- September 2024

2024-09-29 Thread Arturo Borrero Gonzalez
Hello, This is my September 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! LTS: I worked on the nss package for Debian Bullseye, with the following highlights: * briefly evaluated CVE-2023-5388, but t

Debian LTS and ELTS -- September 2024

2024-09-29 Thread Daniel Leidert
Hi, ELTS in September: I worked on CVE-2019-2435, CVE-2024-21090, and CVE-2024-21170 in mysql- connector-python for Stretch. The ELA can be expected next month if the identified patches can be verified by upstream. I also prepared patches for CVE-2024-43167 and CVE-2024-43168 for unbound in Str