Bug#1036811: bullseye-pu: package ncurses/6.2+20201114-2+deb11u2

2023-07-24 Thread Sven Joachim
On 2023-07-24 18:37 +0100, Jonathan Wiltshire wrote: > Control: tag -1 confirmed > > On Fri, May 26, 2023 at 08:51:55PM +0200, Sven Joachim wrote: >> I would like to address CVE-2023-29491[1] aka bug #1034372[2] in >> Bullseye. The changes are the same as in version 6.4-3 (see >> #1035351[3]),

Bug#1036811: bullseye-pu: package ncurses/6.2+20201114-2+deb11u2

2023-07-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Fri, May 26, 2023 at 08:51:55PM +0200, Sven Joachim wrote: > I would like to address CVE-2023-29491[1] aka bug #1034372[2] in > Bullseye. The changes are the same as in version 6.4-3 (see > #1035351[3]), except that there is no need to patch configure.in this > time.

Bug#1036811: bullseye-pu: package ncurses/6.2+20201114-2+deb11u2

2023-07-23 Thread Sven Joachim
On 2023-07-23 14:12 +0100, Jonathan Wiltshire wrote: > Control: tag -1 moreinfo > > On Fri, May 26, 2023 at 08:51:55PM +0200, Sven Joachim wrote: >> [ Risks ] >> Users who are relying on their own terminfo files under >> ${HOME}/.terminfo can no longer use them in setuid/setgid programs and >>

Bug#1036811: bullseye-pu: package ncurses/6.2+20201114-2+deb11u2

2023-07-23 Thread Jonathan Wiltshire
Control: tag -1 moreinfo On Fri, May 26, 2023 at 08:51:55PM +0200, Sven Joachim wrote: > [ Risks ] > Users who are relying on their own terminfo files under > ${HOME}/.terminfo can no longer use them in setuid/setgid programs and > will have to work around that, e.g. by changing their TERM

Bug#1036811: bullseye-pu: package ncurses/6.2+20201114-2+deb11u2

2023-05-26 Thread Sven Joachim
Package: release.debian.org Severity: normal Tags: bullseye d-i User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: ncur...@packages.debian.org, debian-b...@lists.debian.org Control: affects -1 + src:ncurses I would like to address CVE-2023-29491[1] aka bug #1034372[2] in