Bug#987353: CVE-2020-8903 CVE-2020-8907 CVE-2020-8933

2021-05-16 Thread Theodore Y. Ts'o
On Thu, May 13, 2021 at 09:56:53PM +0100, Marcin Kulisz wrote: > > I hope that we're be able to change it, but for me fundamental > question is if Google is interested in participating in effort to > keep those packages in Debian main and if so what resources can be > committed to do so. From my

Bug#987353: CVE-2020-8903 CVE-2020-8907 CVE-2020-8933

2021-05-13 Thread Marcin Kulisz
On 2021-05-10 12:16:09, Noah Meyerhans wrote: > On Mon, May 10, 2021 at 09:00:34PM +0200, Moritz Mühlenhoff wrote: > > > Hi, since this package was brought into Debian in ~2018, there have been > > > several transformations in the GCE guest software stack and thus the > > > current landscape is

Bug#987353: CVE-2020-8903 CVE-2020-8907 CVE-2020-8933

2021-05-10 Thread Noah Meyerhans
On Mon, May 10, 2021 at 09:00:34PM +0200, Moritz Mühlenhoff wrote: > > Hi, since this package was brought into Debian in ~2018, there have been > > several transformations in the GCE guest software stack and thus the > > current landscape is very different. Google doesn't actually maintain the > >

Bug#987353: CVE-2020-8903 CVE-2020-8907 CVE-2020-8933

2021-05-10 Thread Moritz Mühlenhoff
Am Thu, Apr 22, 2021 at 09:53:24AM -0700 schrieb Zach Marano: > Hi, since this package was brought into Debian in ~2018, there have been > several transformations in the GCE guest software stack and thus the > current landscape is very different. Google doesn't actually maintain the > official

Bug#987353: CVE-2020-8903 CVE-2020-8907 CVE-2020-8933

2021-04-22 Thread Moritz Muehlenhoff
Source: google-compute-image-packages Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team https://cloud.google.com/compute/docs/security-bulletins#2020619 seems unfixed unstable/bullseye still. Patches: https://github.com/GoogleCloudPlatform/guest-oslogin/pull/29 Cheers,