Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-09-03 Thread Moritz Mühlenhoff
On Mon, Sep 02, 2019 at 10:36:58PM +0200, Salvatore Bonaccorso wrote: > Hi Chris, > > On Mon, Sep 02, 2019 at 02:07:55PM +0100, Chris Lamb wrote: > > Chris Lamb wrote: > > > > > > > +python-django (1:1.11.23-1~deb10u1) buster-security; urgency=high > > > > > > > > Thanks, these both look good;

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-09-02 Thread Salvatore Bonaccorso
Hi Chris, On Mon, Sep 02, 2019 at 02:07:55PM +0100, Chris Lamb wrote: > Chris Lamb wrote: > > > > > +python-django (1:1.11.23-1~deb10u1) buster-security; urgency=high > > > > > > Thanks, these both look good; please upload to security-master. > > > > Both uploaded to security-master. > >

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-09-02 Thread Chris Lamb
Chris Lamb wrote: > > > +python-django (1:1.11.23-1~deb10u1) buster-security; urgency=high > > > > Thanks, these both look good; please upload to security-master. > > Both uploaded to security-master. There is now a 1.11.24 (ie. 1:1.11.24-1~deb10u1) upstream:

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-10 Thread Chris Lamb
Hi Sébastien, > > +python-django (1:1.10.7-2+deb9u5) stretch-security; urgency=high > > [...] > > +python-django (1:1.11.23-1~deb10u1) buster-security; urgency=high > > Thanks, these both look good; please upload to security-master. Both uploaded to security-master. Regards, -- ,''`.

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-10 Thread Sébastien Delafond
On 08/08 11:02, Chris Lamb wrote: > +python-django (1:1.10.7-2+deb9u5) stretch-security; urgency=high > [...] > +python-django (1:1.11.23-1~deb10u1) buster-security; urgency=high Thanks, these both look good; please upload to security-master. Cheers, -- Seb

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-09 Thread Chris Lamb
Hi Salvatore, > Although I'm late for the game ;-). You can use both > 1:1.11.23-1~deb10u1 or 1:1.11.23-0+deb10u1. It is a matter of what you > want the oxpress. > > 1:1.11.23-1~deb10u1 ... is mainly are rebuild of 1:1.11.23-1 with > maybe some additional changes. Examples for this one are e.g.

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Salvatore Bonaccorso
Hi, On Thu, Aug 08, 2019 at 02:16:29PM +0100, Chris Lamb wrote: > Hi Moritz, > > > > > > Security team (added to CC), would you be interested in uploads for > > > > > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > > > > > 1:1.10.7-2+deb9u5)? > […] > > I just realised that

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
Hi Moritz et al., > > > > > > Security team (added to CC), would you be interested in uploads for > > > > > > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > > > > > > 1:1.10.7-2+deb9u5)? > > […] > > > I just realised that there's a 1.11.23 (thanks Salvatore!), given that > > >

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Moritz Muehlenhoff
On Thu, Aug 08, 2019 at 02:16:29PM +0100, Chris Lamb wrote: > Hi Moritz, > > > > > > Security team (added to CC), would you be interested in uploads for > > > > > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > > > > > 1:1.10.7-2+deb9u5)? > […] > > I just realised that there's a

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
Hi Moritz, > > > > I mention it specifically as I'm not 100% confident this is correct > > > > and Lintian somewhat-correctly complained about a "missing" version > > > > (to wit, 1:1.11.22-1 its technically missing). […] > Got it. From my PoV Lintian should probably just waive that check >

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
Hi Moritz, > > > > Security team (added to CC), would you be interested in uploads for > > > > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > > > > 1:1.10.7-2+deb9u5)? […] > I just realised that there's a 1.11.23 (thanks Salvatore!), given that > we agreed to follow 1.11.x in

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Moritz Muehlenhoff
On Thu, Aug 08, 2019 at 11:02:48AM +0100, Chris Lamb wrote: > Hi Sébastien, > > > > Security team (added to CC), would you be interested in uploads for > > > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > > > 1:1.10.7-2+deb9u5)? > […] > > yes, thank you. Can you email us debdiffs

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Moritz Muehlenhoff
On Thu, Aug 08, 2019 at 11:22:37AM +0100, Chris Lamb wrote: > Moritz Muehlenhoff wrote: > > > > I mention it specifically as I'm not 100% confident this is correct > > > and Lintian somewhat-correctly complained about a "missing" version > > > (to wit, 1:1.11.22-1 its technically missing). > > >

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
Moritz Muehlenhoff wrote: > > I mention it specifically as I'm not 100% confident this is correct > > and Lintian somewhat-correctly complained about a "missing" version > > (to wit, 1:1.11.22-1 its technically missing). > > Where does Lintian parse the data about existing releases? How does it

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Moritz Muehlenhoff
On Thu, Aug 08, 2019 at 11:02:48AM +0100, Chris Lamb wrote: > Hi Sébastien, > > > > Security team (added to CC), would you be interested in uploads for > > > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > > > 1:1.10.7-2+deb9u5)? > […] > > yes, thank you. Can you email us debdiffs

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
Hi Sébastien, > > Security team (added to CC), would you be interested in uploads for > > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > > 1:1.10.7-2+deb9u5)? […] > yes, thank you. Can you email us debdiffs ? I'll then take care of the > review and DSAs. I've attached these and

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-07 Thread Sébastien Delafond
On 06/08 10:20, Chris Lamb wrote: > Security team (added to CC), would you be interested in uploads for > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > 1:1.10.7-2+deb9u5)? Hi Chris, yes, thank you. Can you email us debdiffs ? I'll then take care of the review and DSAs. Cheers,

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-06 Thread Chris Lamb
[Adding t...@security.debian.org to CC] Chris Lamb wrote: > The following vulnerabilities were published for python-django. > > CVE-2019-14232[0]: > CVE-2019-14233[1]: > CVE-2019-14234[2]: > CVE-2019-14235[3]: I have just fixed this in sid and will fix this in jessie LTS shortly. Security

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-06 Thread Chris Lamb
Package: python-django Version: 1.7.11-1+deb8u6 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for python-django. CVE-2019-14232[0]: | An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before | 2.1.11, and