Bug#988730: CVE-2017-18641

2024-03-18 Thread Salvatore Bonaccorso
Hi Mathias,

On Sun, Mar 17, 2024 at 05:41:30PM +, Mathias Gibbens wrote:
> On Sun, 2024-01-28 at 08:44 +0100, Salvatore Bonaccorso wrote:
> > Thanks for the update. Do you know of any plans of making
> > distrobuilder available?
> 
>   distrobuilder is now available in both testing and unstable. I'll be
> reaching out to some of the users of lxc-templates to let them know and
> suggesting that they migrate to using distrobuilder.

Thanks for your update!

Regards,
Salvatore



Bug#988730: CVE-2017-18641

2024-03-17 Thread Mathias Gibbens
On Sun, 2024-01-28 at 08:44 +0100, Salvatore Bonaccorso wrote:
> Thanks for the update. Do you know of any plans of making
> distrobuilder available?

  distrobuilder is now available in both testing and unstable. I'll be
reaching out to some of the users of lxc-templates to let them know and
suggesting that they migrate to using distrobuilder.

Mathias


signature.asc
Description: This is a digitally signed message part


Bug#988730: CVE-2017-18641

2024-01-28 Thread Mathias Gibbens
On Sun, 2024-01-28 at 08:44 +0100, Salvatore Bonaccorso wrote:
> Thanks for the update. Do you know of any plans of making
> distrobuilder available?

  Up to this point I don't know of anything concrete. There are a few
references over the years of people's desire to package it, but nothing
much more appears to have happened. I will file an ITP shortly for
distrobuilder, so it's at least on my radar to work on at some point in
the future.

Mathias


signature.asc
Description: This is a digitally signed message part


Bug#988730: CVE-2017-18641

2024-01-27 Thread Salvatore Bonaccorso
Hi,

On Sun, Jan 28, 2024 at 12:51:58AM +, Mathias Gibbens wrote:
> Control: tags -1 + wontfix
> 
>   lxc-templates is essentially deprecated upstream in favor of
> distrobuilder. From the launchpad discussion:

Thanks for the update. Do you know of any plans of making
distrobuilder available?

Regards,
Salvatore



Bug#988730: CVE-2017-18641

2024-01-27 Thread Mathias Gibbens
Control: tags -1 + wontfix

  lxc-templates is essentially deprecated upstream in favor of
distrobuilder. From the launchpad discussion:

On 2020-02-05, Stéphane Graber wrote:
> Back in LXC 3.0 we moved the legacy template scripts to their own
> repository at https://github.com/lxc/lxc-templates and they are now
> community maintained without security/lts commitments on them on our
> side. Ubuntu still ships lxc-templates but it does so in universe
> rather than main, matching the upstream commitment.

  And there was a discussion in debian-lts[1] about marking this CVE as
no-dsa or ignored, which is how things are flagged in the security
tacker.

  Given the amount of work required for very little gain and an
inactive upstream, I'm tagging this bug as wontfix.

Mathias

[1] -- https://lists.debian.org/debian-lts/2020/02/msg00102.html


signature.asc
Description: This is a digitally signed message part


Bug#988730: CVE-2017-18641

2021-05-18 Thread Moritz Muehlenhoff
Package: lxc-templates
Severity: important
Tags: security
X-Debbugs-Cc: Debian Security Team 

https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1661447

This was originally for LXC, but with 3.0.2 the templates are now in
lxc-templates.

Cheers,
Moritz