Bug#1031948: bullseye-pu: package libgit2/1.1.0+dfsg.1-4+deb11u1

2023-04-02 Thread Tobias Frost
On Sat, Apr 01, 2023 at 08:13:23PM +0100, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Sat, 2023-02-25 at 21:16 +0100, Tobias Frost wrote: > > After fixing CVE-2023-22742 for LTS and ELTS, I'd like to see > > this CVE also fixed in stable, for consistency. > > > > The CVE is an in

Bug#1031948: bullseye-pu: package libgit2/1.1.0+dfsg.1-4+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2023-02-25 at 21:16 +0100, Tobias Frost wrote: > After fixing CVE-2023-22742 for LTS and ELTS, I'd like to see > this CVE also fixed in stable, for consistency. > > The CVE is an inproper ssh certificate validation vulnerabilty, > which allows man-in-the-middl

Bug#1031948: bullseye-pu: package libgit2/1.1.0+dfsg.1-4+deb11u1

2023-02-25 Thread Tobias Frost
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: libg...@packages.debian.org Control: affects -1 + src:libgit2 After fixing CVE-2023-22742 for LTS and ELTS, I'd like to see this CVE also fixed in stable, for consist