CVE-2023-46604/activemq

2024-10-07 Thread Santiago Ruano Rincón
Dear teams, activemq is listed in both dla-needed and dsa-needed, and I claimed it for bullseye LTS. CVE-2023-46604 was fixed in 5.17.6 and 5.16.7 and the patches for both are clearly identified upstream: d0ccdd31544ada83185554c87c7aa141064020f0 (activemq-5.17.6) (as noted in the sectracker) 2244

Question about risk of regression for git

2024-10-07 Thread Ola Lundqvist
Hi fellow LTS and ELTS developers I started to look at git for bullseye. It has one vulnerability in CVE-2024-32020. You can read about the vulnerability here: https://security-tracker.debian.org/tracker/CVE-2024-32020 For Debian Stable it has been fixed together with a lot of other changes in th

Re: CVE-2023-46604/activemq

2024-10-07 Thread Pierre Gruet
Hi Santiago, Le 07/10/2024 à 20:21, Santiago Ruano Rincón a écrit : Dear teams, activemq is listed in both dla-needed and dsa-needed, and I claimed it for bullseye LTS. CVE-2023-46604 was fixed in 5.17.6 and 5.16.7 and the patches for both are clearly identified upstream: [...] I have also