Bug#1021266: curl CVE patches applied at curl 7.74.0-1.3+deb11u2 breaks janus package working with RTSP sources

2022-11-15 Thread Markus Koschany
Hello Samuel,

Am Dienstag, dem 15.11.2022 um 20:47 + schrieb Samuel Henrique:
> Hello Markus,
> 
> Would you have some time to investigate this issue, please?
> 
> Thank you, (and thank you Raimon for reporting this)

We need to CC Raimon because bug reporters are not automatically subscribed to
bug reports.

janus is not supported in Debian stable. There is only a version in stable-
backports. Without a clear reproducer of an affected package in stable, I can't
debug this issue.

Regards,

Markus



signature.asc
Description: This is a digitally signed message part


Bug#1021266: curl CVE patches applied at curl 7.74.0-1.3+deb11u2 breaks janus package working with RTSP sources

2022-11-15 Thread Samuel Henrique
Hello Markus,

Would you have some time to investigate this issue, please?

Thank you, (and thank you Raimon for reporting this)

-- 
Samuel Henrique 



Bug#1021266: curl CVE patches applied at curl 7.74.0-1.3+deb11u2 breaks janus package working with RTSP sources

2022-10-04 Thread Raimon Alba
Package: curl
Version: 7.74.0-1.3+deb11u2
Severity: important

Dear Maintainer,


   * What led up to the situation? Updating system to lastest official
packages for Debian bullseye upgraded curl/libcurl first to
7.74.0-1.3+deb11u2 and later to 7.74.0-1.3-deb11u3 both resulting in
package janus using RTSP sources stop working with zoneminder.
   * What exactly did you do (or not do) that was effective (or
ineffective)? Downgrading to 7.74.0-1.3+deb11u1 made it work again without
touching any thing.
   * What was the outcome of this action?. Simply downgrading maintainer
version made it work. So should be anything between deb11u1 and deb11u2
version.
   * What outcome did you expect instead?



-- System Information:
Debian Release: 11.5
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500,
'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-18-amd64 (SMP w/6 CPU threads)
Locale: LANG=es_ES.UTF-8, LC_CTYPE=es_ES.UTF-8 (charmap=UTF-8), LANGUAGE
not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages curl depends on:
ii  libc6 2.31-13+deb11u4
ii  libcurl4  7.74.0-1.3+deb11u2
ii  zlib1g1:1.2.11.dfsg-2+deb11u2

curl recommends no packages.

curl suggests no packages.

-- no debconf information

--1664908316-eximdsn-417993741--