Re: Bug#1073508: Bug#1074338: src:libxml2: fails to migrate to testing for too long: unresolved RC issue

2024-08-17 Thread Paul Gevers
Hi, [Disclaimer: I'm not the most experienced person on transitions in the team, so I'd like for Graham, Emilio and/or Sebastian to check if they agree with me.] Thanks for working on this. On 17-08-2024 05:58, Aron Xu wrote: After some research, I prefer making a t64-like transition for li

Processed: reopening 1069891, tagging 1069891, reopening 1070193, tagging 1070193

2024-08-17 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reopen 1069891 Bug #1069891 {Done: Lee Garrett } [release.debian.org] bookworm-pu: package ansible/7.7.0+dfsg-3+deb12u1 'reopen' may be inappropriate when a bug has been closed with a version; all fixed versions will be cleared, and you may need

Re: Bug#1074338: Bug#1073508: Bug#1074338: src:libxml2: fails to migrate to testing for too long: unresolved RC issue

2024-08-17 Thread Aron Xu
On Sat, Aug 17, 2024 at 5:15 PM Paul Gevers wrote: > > Hi, > > [Disclaimer: I'm not the most experienced person on transitions in the > team, so I'd like for Graham, Emilio and/or Sebastian to check if they > agree with me.] > > Thanks for working on this. > > On 17-08-2024 05:58, Aron Xu wrote: >

Bug#1076156: bookworm-pu: package imagemagick/8:6.9.11.60+dfsg-1.6+deb12u2

2024-08-17 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2024-07-11 at 17:16 +, Bastien Roucariès wrote: >   * CVE-2023-34151 fix was incomplete (Closes: #1070340) >   * Fix variation of CVE-2023-1289 found by testing. Please go ahead. Regards, Adam

Processed: Re: Bug#1076156: bookworm-pu: package imagemagick/8:6.9.11.60+dfsg-1.6+deb12u2

2024-08-17 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1076156 [release.debian.org] bookworm-pu: package imagemagick/8:6.9.11.60+dfsg-1.6+deb12u2 Added tag(s) confirmed. -- 1076156: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1076156 Debian Bug Tracking System Contact ow...@bugs.debian.o

Processed: Re: Bug#1076345: bookworm-pu: graphviz/2.42.2-7+deb12u1

2024-08-17 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1076345 [release.debian.org] bookworm-pu: graphviz/2.42.2-7+deb12u1 Added tag(s) confirmed. -- 1076345: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1076345 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1076345: bookworm-pu: graphviz/2.42.2-7+deb12u1

2024-08-17 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2024-07-14 at 20:52 +0200, László Böszörményi wrote: > [ Reason ] > Graphviz scaling output with SVG is wrong when the "size" attribute > is set. Please go ahead. Regards, Adam

Bug#1077509: bookworm-pu: package cyrus-imapd/3.6.1-4+deb12u3

2024-08-17 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2024-07-29 at 17:55 +0400, Yadd wrote: > There was a regression introduced by CVE-2024-34055 which breaks > Cyrus-Imapd's murder (RC bug #1075853). Please go ahead. Regards, Adam

Bug#1076504: bookworm-pu: package qemu/1:7.2+dfsg-7+deb12u7

2024-08-17 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2024-07-17 at 15:15 +0300, Michael Tokarev wrote: > [ Reason ] > There were 2 qemu stable/bugfix releases (7.2.12 and 7.2.13) since > the previous debian release, fixing a number of various issues. > It would be nice to have these fixes in debian too, so debian

Processed: Re: Bug#1076504: bookworm-pu: package qemu/1:7.2+dfsg-7+deb12u7

2024-08-17 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1076504 [release.debian.org] bookworm-pu: package qemu/1:7.2+dfsg-7+deb12u7 Added tag(s) confirmed. -- 1076504: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1076504 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Processed: Re: Bug#1077509: bookworm-pu: package cyrus-imapd/3.6.1-4+deb12u3

2024-08-17 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1077509 [release.debian.org] bookworm-pu: package cyrus-imapd/3.6.1-4+deb12u3 Added tag(s) confirmed. -- 1077509: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1077509 Debian Bug Tracking System Contact ow...@bugs.debian.org with probl

Processed: Re: Bug#1077515: bookworm-pu: package putty/0.78-2+deb12u2

2024-08-17 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1077515 [release.debian.org] bookworm-pu: package putty/0.78-2+deb12u2 Added tag(s) confirmed. -- 1077515: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1077515 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1077515: bookworm-pu: package putty/0.78-2+deb12u2

2024-08-17 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2024-07-29 at 15:32 +, Bastien Roucariès wrote: > Security fix CVE-2024-31497 Please go ahead. Regards, Adam

Bug#1077549: bookworm-pu: package xmedcon/0.23.0-gtk3+dfsg-1+deb12u1

2024-08-17 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2024-07-29 at 23:00 +0200, Étienne Mollier wrote: > xmedcon in bookworm is affected by CVE-2024-29421.  It is, > quoting the description: "vulnerable to Buffer Overflow via > libs/dicom/basic.c which allows an attacker to execute arbitrary > code".  It is curre

Processed: Re: Bug#1077549: bookworm-pu: package xmedcon/0.23.0-gtk3+dfsg-1+deb12u1

2024-08-17 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1077549 [release.debian.org] bookworm-pu: package xmedcon/0.23.0-gtk3+dfsg-1+deb12u1 Added tag(s) confirmed. -- 1077549: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1077549 Debian Bug Tracking System Contact ow...@bugs.debian.org wit

Bug#1078176: bookworm-pu: package dcm2niix/1.0.20220720-1+deb12u1

2024-08-17 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2024-08-07 at 23:24 +0200, Étienne Mollier wrote: > dcm2niix is affected by minor security issue CVE-2024-27629 in > bookworm: a local attacker can execute arbitrary code as the > generated file name is not properly escaped and injected into a > system call whe

Processed: Re: Bug#1078176: bookworm-pu: package dcm2niix/1.0.20220720-1+deb12u1

2024-08-17 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1078176 [release.debian.org] bookworm-pu: package dcm2niix/1.0.20220720-1+deb12u1 Added tag(s) confirmed. -- 1078176: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1078176 Debian Bug Tracking System Contact ow...@bugs.debian.org with p

Bug#1078781: bookworm-pu: package amd64-microcode/3.20240710.2~deb12u1

2024-08-17 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2024-08-15 at 22:24 -0300, Henrique de Moraes Holschuh wrote: > As requested by the security team, I would like to bring the > *firmware* update level for AMD processors in Bullseye and Bookworm > to match what we have in Sid and Trixie.  This is the bug report

Processed: Re: Bug#1078781: bookworm-pu: package amd64-microcode/3.20240710.2~deb12u1

2024-08-17 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1078781 [release.debian.org] bookworm-pu: package amd64-microcode/3.20240710.2~deb12u1 Added tag(s) confirmed. -- 1078781: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1078781 Debian Bug Tracking System Contact ow...@bugs.debian.org w

Bug#1078782: bullseye-pu: package amd64-microcode/3.20240710.2~deb11u1

2024-08-17 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2024-08-15 at 22:26 -0300, Henrique de Moraes Holschuh wrote: > As requested by the security team, I would like to bring the > *firmware* update level for AMD processors in Bullseye and Bookworm > to match what we have in Sid and Trixie.  This is the bug report

Processed: Re: Bug#1078782: bullseye-pu: package amd64-microcode/3.20240710.2~deb11u1

2024-08-17 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1078782 [release.debian.org] bullseye-pu: package amd64-microcode/3.20240710.2~deb11u1 Added tag(s) confirmed. -- 1078782: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1078782 Debian Bug Tracking System Contact ow...@bugs.debian.org w

Bug#1077549: bookworm-pu: package xmedcon/0.23.0-gtk3+dfsg-1+deb12u1

2024-08-17 Thread Étienne Mollier
Hi Adam, Adam D. Barratt, on 2024-08-17: > On Mon, 2024-07-29 at 23:00 +0200, Étienne Mollier wrote: > > xmedcon in bookworm is affected by CVE-2024-29421.  It is, > > quoting the description: "vulnerable to Buffer Overflow via > > libs/dicom/basic.c which allows an attacker to execute arbitrary >

Bug#1078176: bookworm-pu: package dcm2niix/1.0.20220720-1+deb12u1

2024-08-17 Thread Étienne Mollier
Adam D. Barratt, on 2024-08-17: > On Wed, 2024-08-07 at 23:24 +0200, Étienne Mollier wrote: > > dcm2niix is affected by minor security issue CVE-2024-27629 in > > bookworm: a local attacker can execute arbitrary code as the > > generated file name is not properly escaped and injected into a > > sys

Bug#1078781: bookworm-pu: package amd64-microcode/3.20240710.2~deb12u1

2024-08-17 Thread Henrique de Moraes Holschuh
Uploaded! Thank you! On Sat, Aug 17, 2024, at 13:46, Adam D. Barratt wrote: > Control: tags -1 + confirmed

Bug#1078782: bullseye-pu: package amd64-microcode/3.20240710.2~deb11u1

2024-08-17 Thread Henrique de Moraes Holschuh
Uploaded. Thank you! On Sat, Aug 17, 2024, at 13:47, Adam D. Barratt wrote: > Control: tags -1 + confirmed -- Henrique de Moraes Holschuh

Bug#1077515: bookworm-pu: package putty/0.78-2+deb12u2

2024-08-17 Thread Bastien Roucariès
Le samedi 17 août 2024, 16:38:10 UTC Adam D. Barratt a écrit : > Control: tags -1 + confirmed > > On Mon, 2024-07-29 at 15:32 +, Bastien Roucariès wrote: > > Security fix CVE-2024-31497 Done > > Please go ahead. > > Regards, > > Adam > signature.asc Description: This is a digitally sign

Processed: bookworm-pu: package openssl/3.0.14-1~deb12u1

2024-08-17 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + src:openssl Bug #1078937 [release.debian.org] bookworm-pu: package openssl/3.0.14-1~deb12u1 Added indication that 1078937 affects src:openssl -- 1078937: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1078937 Debian Bug Tracking System Contact ow...

Bug#1075828: bookworm-pu: package openssl/3.0.13-1~deb12u2

2024-08-17 Thread Sebastian Andrzej Siewior
On 2024-08-14 21:05:28 [+0100], Adam D. Barratt wrote: > Sorry for the delay. No worries, thank you for handling it. > I've just flagged the bugfix upload for acceptance into p-u. If you'd > like to look at 3.0.14 as well, please open a new bug for that. If it > makes any difference, the window f