Bug#981664: buster-pu: package privoxy/3.0.28-2

2021-03-13 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2021-03-08 at 14:08 +0100, Roland Rosenfeld wrote: > Hi release team! > > In the meantime privoxy 3.0.32 was released, which contains five more > CVEs, I applied four of them to 3.0.28-2+deb10u1.patch-v4 now, while > CVE-2021-20274 applies to code, that was

Bug#981664: buster-pu: package privoxy/3.0.28-2

2021-03-08 Thread Roland Rosenfeld
Hi release team! In the meantime privoxy 3.0.32 was released, which contains five more CVEs, I applied four of them to 3.0.28-2+deb10u1.patch-v4 now, while CVE-2021-20274 applies to code, that was introduced in 3.0.29, so doesn't affect buster. An updated version of my patch is attached.

Bug#981664: buster-pu: package privoxy/3.0.28-2

2021-02-06 Thread Roland Rosenfeld
Hi! > > yesterday upstream assigned a few additional CVE IDs (also no-dsa): > > https://www.openwall.com/lists/oss-security/2021/02/03/3, maybe you > > also want to fold these in? > > You're right, I just did so and updated the buster package to > incorporate all additional patches. > > An

Bug#981664: buster-pu: package privoxy/3.0.28-2

2021-02-04 Thread Roland Rosenfeld
Hi Moritz! On Do, 04 Feb 2021, Moritz Mühlenhoff wrote: > Am Tue, Feb 02, 2021 at 07:15:37PM +0100 schrieb Roland Rosenfeld: > > Package: release.debian.org > > Severity: normal > > Tags: buster > > User: release.debian@packages.debian.org > > Usertags: pu > > > > This fixes CVE-2021-20216

Bug#981664: buster-pu: package privoxy/3.0.28-2

2021-02-04 Thread Moritz Mühlenhoff
Am Tue, Feb 02, 2021 at 07:15:37PM +0100 schrieb Roland Rosenfeld: > Package: release.debian.org > Severity: normal > Tags: buster > User: release.debian@packages.debian.org > Usertags: pu > > This fixes CVE-2021-20216 and CVE-2021-20217. > Since both are tagged " (Minor issue)" in security

Bug#981664: buster-pu: package privoxy/3.0.28-2

2021-02-02 Thread Roland Rosenfeld
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu This fixes CVE-2021-20216 and CVE-2021-20217. Since both are tagged " (Minor issue)" in security tracker, I tend to send this into the next point release of buster. Salsa-CI