Bug#1091765: bookworm-pu: package python-tornado/6.2.0-3+deb12u1

2024-12-30 Thread Daniel Leidert
access a specially + crafted URL. + + -- Daniel Leidert Tue, 31 Dec 2024 01:53:59 +0100 + python-tornado (6.2.0-3) unstable; urgency=medium [ Debian Janitor ] diff -Nru python-tornado-6.2.0/debian/gbp.conf python-tornado-6.2.0/debian/gbp.conf --- python-tornado-6.2.0/debian/gbp.conf

Bug#1091764: bookworm-pu: package setuptools/66.1.1-1+deb12u1

2024-12-30 Thread Daniel Leidert
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: setupto...@packages.debian.org Control: affects -1 + src:setuptools User: release.debian@packages.debian.org Usertags: pu -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 [ Reason ] CVE-2024-6345 has been fixed in oldsta

Bug#1091800: bookworm-pu: package python-asyncssh/2.10.1-2+deb12u2

2024-12-31 Thread Daniel Leidert
additional restrictions on when messages are accepted during the + SSH handshake to avoid message injection attacks from a rogue client + or server (closes: #1055999, #1056000). + + -- Daniel Leidert Tue, 31 Dec 2024 14:12:00 +0100 + python-asyncssh (2.10.1-2+deb12u1) bookworm-security

Bug#1098783: bookworm-pu: package fort-validator/1.5.4-1+deb12u1

2025-02-23 Thread Daniel Leidert
validation run by drip-feeding its content. This can lead to delayed + validation and a stale or unavailable Route Origin Validation. + (thanks to Jochen Sprickerhof for helping backporting the test case) + + -- Daniel Leidert Mon, 24 Feb 2025 01:34:04 +0100 + fort-validator (1.

Bug#1098783: bookworm-pu: package fort-validator/1.5.4-1+deb12u1

2025-03-27 Thread Daniel Leidert
Hi Adam, thanks for going through the PU. Am Samstag, dem 01.03.2025 um 10:57 + schrieb Adam D. Barratt: > Control: tags -1 + moreinfo > > On Mon, 2025-02-24 at 02:40 +0100, Daniel Leidert wrote: > > There are multiple known CVEs (CVE-2024-45234, CVE-2024-45235, CVE- >

<    1   2