Re: libssh CVE-2023-6004, CVE-2023-6918, CVE-2023-48795

2023-12-24 Thread Moritz Muehlenhoff
[ You missed the correct mailing list. debian-security is _not_ the correct way to reach the security team, fixing ] On Sun, Dec 24, 2023 at 09:12:04AM +, Sean Whitton wrote: > Hello, > > I have taken responsibility for fixing these CVEs in libssh in buster, > as part of Freexian-funded

libssh CVE-2023-6004, CVE-2023-6918, CVE-2023-48795

2023-12-24 Thread Sean Whitton
Hello, I have taken responsibility for fixing these CVEs in libssh in buster, as part of Freexian-funded LTS work. I would like to see if I can help get them fixed in bullseye & bookworm in parallel, to avoid a situation where they're fixed in buster but not fixed in releases to which LTS users