Bug#951800: CVE-2020-9273: buster affected

2020-02-26 Thread Salvatore Bonaccorso
Hi Hilmar, On Wed, Feb 26, 2020 at 06:41:05PM +0100, Salvatore Bonaccorso wrote: > Hi HIlmar, > > On Tue, Feb 25, 2020 at 06:20:06PM +0100, Hilmar Preuße wrote: > > On 2/22/20 10:58 PM, Salvatore Bonaccorso wrote: > > > On Sat, Feb 22, 2020 at 09:29:34PM +0100, Hilmar Preuße wrote: > > > > Hi

Bug#951800: CVE-2020-9273: buster affected

2020-02-26 Thread Salvatore Bonaccorso
Hi HIlmar, On Tue, Feb 25, 2020 at 06:20:06PM +0100, Hilmar Preuße wrote: > On 2/22/20 10:58 PM, Salvatore Bonaccorso wrote: > > On Sat, Feb 22, 2020 at 09:29:34PM +0100, Hilmar Preuße wrote: > > Hi Salvatore, > > >> The fix for this issue (+ patch for two other issues) is already in the > >>

Bug#951800: CVE-2020-9273: buster affected

2020-02-25 Thread Hilmar Preuße
On 2/22/20 10:58 PM, Salvatore Bonaccorso wrote: > On Sat, Feb 22, 2020 at 09:29:34PM +0100, Hilmar Preuße wrote: Hi Salvatore, >> The fix for this issue (+ patch for two other issues) is already in the >> buster branch on salsa. I planned to upload that ASAP. Not sure if it >> will still happen

Bug#951800: CVE-2020-9273: buster affected

2020-02-22 Thread Salvatore Bonaccorso
Hi Hilmar, On Sat, Feb 22, 2020 at 09:29:34PM +0100, Hilmar Preuße wrote: > On 2/22/20 5:52 PM, Salvatore Bonaccorso wrote: > > On Fri, Feb 21, 2020 at 10:07:42PM +0100, Hilmar Preusse wrote: > > Hi Salvatore, > > >> Package: proftpd-basic > >> Version: 1.3.6-4+deb10u3 > >> Severity: important

Bug#951800: CVE-2020-9273: buster affected

2020-02-22 Thread Hilmar Preuße
On 2/22/20 5:52 PM, Salvatore Bonaccorso wrote: > On Fri, Feb 21, 2020 at 10:07:42PM +0100, Hilmar Preusse wrote: Hi Salvatore, >> Package: proftpd-basic >> Version: 1.3.6-4+deb10u3 >> Severity: important >> Tags: upstream >> >> This is to track CVE-2020-9273. >> >> I'm not 100% sure if jessie

Bug#951800: CVE-2020-9273: buster affected

2020-02-21 Thread Hilmar Preusse
Package: proftpd-basic Version: 1.3.6-4+deb10u3 Severity: important Tags: upstream This is to track CVE-2020-9273. I'm not 100% sure if jessie is affected too. At least the CVE does not report it. Hilmar -- System Information: Debian Release: bullseye/sid APT prefers unstable APT policy: