Bug#1024632: [Pkg-erlang-devel] Bug#1024632: Bug#1024632: Bug#1024632: erlang: CVE-2022-37026 Client Authentication Bypass

2022-12-14 Thread Sergei Golovan
Hi! On Mon, Dec 12, 2022 at 5:27 PM Sergei Golovan wrote: > > Hi Salvatore, > > On Fri, Dec 9, 2022 at 12:15 AM Salvatore Bonaccorso > wrote: > > > > The upcoming point release for 11.6 is scheduled for 17th with > > uploading window closing the upcoming weekend. If we are confident > > enough

Bug#1024632: [Pkg-erlang-devel] Bug#1024632: Bug#1024632: erlang: CVE-2022-37026 Client Authentication Bypass

2022-12-12 Thread Sergei Golovan
Hi Salvatore, On Fri, Dec 9, 2022 at 12:15 AM Salvatore Bonaccorso wrote: > > The upcoming point release for 11.6 is scheduled for 17th with > uploading window closing the upcoming weekend. If we are confident > enough about potential regressions, can you make sure the fix land in > the next

Bug#1024632: [Pkg-erlang-devel] Bug#1024632: erlang: CVE-2022-37026 Client Authentication Bypass

2022-12-08 Thread Salvatore Bonaccorso
Sergei, Markus, On Wed, Nov 30, 2022 at 04:25:17PM +0300, Sergei Golovan wrote: > Hi Markus, > > On Wed, Nov 30, 2022 at 4:15 PM Markus Koschany wrote: > > > > Hello, > > > > I have prepared a security update for Bullseye which fixes CVE-2022-37026. > > Sergei could you review the update

Bug#1024632: [Pkg-erlang-devel] Bug#1024632: erlang: CVE-2022-37026 Client Authentication Bypass

2022-11-30 Thread Sergei Golovan
Hi Markus, On Wed, Nov 30, 2022 at 4:15 PM Markus Koschany wrote: > > Hello, > > I have prepared a security update for Bullseye which fixes CVE-2022-37026. > Sergei could you review the update please? I am attaching the debdiff. I'm also preparing a fix for CVE-2022-37026, but I'll gladly

Bug#1024632: erlang: CVE-2022-37026 Client Authentication Bypass

2022-11-30 Thread Markus Koschany
Hello, I have prepared a security update for Bullseye which fixes CVE-2022-37026. Sergei could you review the update please? I am attaching the debdiff. Regards, Markus diff -Nru erlang-23.2.6+dfsg/debian/changelog erlang-23.2.6+dfsg/debian/changelog --- erlang-23.2.6+dfsg/debian/changelog

Bug#1024632: erlang: CVE-2022-37026 Client Authentication Bypass

2022-11-22 Thread Markus Koschany
Package: erlang X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for erlang. Initially the security team triaged this issue as minor but further investigation showed the impact might be much more severe. Red Hat and other vendors