Re: Fix for dnsmasq breakage

2018-07-05 Thread Moritz Schlarb
Hello all, I want to support this request heavily! Another patch variant had been posted in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860064 But it seems there is an upstream fix available, too. Regards, -- Moritz Schlarb Unix-Gruppe | Systembetreuung Zentrum für Datenverarbeitung

Re: [SECURITY] [DLA 4106-1] jetty9 security update

2025-04-05 Thread Moritz Schlarb
Dear Markus, could it be the case that the upload of jetty9:amd64=9.4.57-0+deb11u1 has been built on Bookworm instead of Bullseye? $ apt install jetty9 Reading package lists... Done Building dependency tree... Done Reading state information... Done Some packages could not be installed. This may m

Re: Bug#1102413: libapache2-mod-auth-openidc: CVE-2025-31492

2025-04-16 Thread Moritz Schlarb
4.9.4-0+deb11u5) bullseye-security; urgency=high + + * Fix CVE-2025-31492 +"protected content leakage when using OIDCProviderAuthRequestMethod POST" +Backported applicable portions from upstream fix in +https://github.com/OpenIDC/mod_auth_openidc/commit/b59b8ad63411857090ba1088e23fe4

Re: Bug#1102413: libapache2-mod-auth-openidc: CVE-2025-31492

2025-04-17 Thread Moritz Schlarb
Hey Sylvain, On Wed, 2025-04-16 at 12:40 +0200, Sylvain Beucler wrote: > The patch looks good :) Thanks! > The LTS upload workflow is detailed at: > https://lts-team.pages.debian.net/wiki/Development.html > > As a DD you can do everything by yourself, but if you want I can take > care of the a

Re: Bug#1104484: libapache2-mod-auth-openidc: CVE-2025-3891

2025-05-07 Thread Moritz Schlarb
g 2025-04-16 11:13:22.0 +0200 +++ libapache2-mod-auth-openidc-2.4.9.4/debian/changelog 2025-05-07 14:36:24.0 +0200 @@ -1,3 +1,9 @@ +libapache2-mod-auth-openidc (2.4.9.4-0+deb11u6) bullseye-security; urgency=high + + * Add upstream patch to fix CVE-2025-3891 + + -- Moritz Schlarb We