Bug#977782: buster-pu: package postsrsd/1.5-2

2021-01-31 Thread Tomasz Buchert
On 31/01/21 11:08, Salvatore Bonaccorso wrote: > Hi Oxan, > > On Sat, Jan 30, 2021 at 09:58:23PM +0100, Oxan van Leeuwen wrote: > > Hi, > > > > On 30-01-2021 21:27, Salvatore Bonaccorso wrote: > > > I noticed that today there was an upload to security-master for it. > > > Given our previous

Bug#977782: buster-pu: package postsrsd/1.5-2

2021-01-31 Thread Salvatore Bonaccorso
Hi Oxan, On Sat, Jan 30, 2021 at 09:58:23PM +0100, Oxan van Leeuwen wrote: > Hi, > > On 30-01-2021 21:27, Salvatore Bonaccorso wrote: > > I noticed that today there was an upload to security-master for it. > > Given our previous discussion, was this an oversight? I just have > > rejected the

Bug#977782: buster-pu: package postsrsd/1.5-2

2021-01-30 Thread Oxan van Leeuwen
Hi, On 30-01-2021 21:27, Salvatore Bonaccorso wrote: I noticed that today there was an upload to security-master for it. Given our previous discussion, was this an oversight? I just have rejected the package, could you please upload it for the upcoming point release instead to ftp-master? Ah,

Bug#977782: buster-pu: package postsrsd/1.5-2

2021-01-30 Thread Salvatore Bonaccorso
hi Oxan, On Thu, Dec 31, 2020 at 05:11:13PM +, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Sun, 2020-12-20 at 20:48 +0100, Oxan van Leeuwen wrote: > > Upstream recently discovered a potential remote denial-of-service > > attack in postsrsd (CVE-2020-35573) [1]. Fortunately,

Bug#977782: buster-pu: package postsrsd/1.5-2

2020-12-31 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2020-12-20 at 20:48 +0100, Oxan van Leeuwen wrote: > Upstream recently discovered a potential remote denial-of-service > attack in postsrsd (CVE-2020-35573) [1]. Fortunately, this issue is > currently not exploitable in Debian due to gcc optimizing the >

Bug#977782: buster-pu: package postsrsd/1.5-2

2020-12-20 Thread Oxan van Leeuwen
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Upstream recently discovered a potential remote denial-of-service attack in postsrsd (CVE-2020-35573) [1]. Fortunately, this issue is currently not exploitable in Debian due to