Re: CVE-2023-48795: Backporting strict key exchange to older libssh

2024-01-02 Thread Jakub Jelen
Hi. Thank you for all the good questions! I will try to reply inline. On Sat, Dec 30, 2023 at 8:41 PM Sean Whitton wrote: > > Hello, > > I am working to backport the fix for CVE-2023-48795 to libssh 0.8.7, > as part of Debian's Long Term Support effort, funded by Freexian SARL. > (I will later

Re: (E)?LTS report for december

2024-01-02 Thread Bastien Roucariès
Le mardi 2 janvier 2024, 14:53:22 UTC Bastien Roucariès a écrit : Hi, Obviously the report should be read for decembre 2023 > I've worked during november 2023 on the below listed packages, for Freexian > LTS/ELTS [1] > > Many thanks to Freexian and our sponsors [2] for providing this

(E)?LTS report for november

2024-01-02 Thread Bastien Roucariès
I've worked during november 2023 on the below listed packages, for Freexian LTS/ELTS [1] Many thanks to Freexian and our sponsors [2] for providing this opportunity! ELTS: The work consisted to fix libreoffice both for stretch and jessie. I have fixed CVE-2020-12801 CVE-2020-12802

Debian LTS and ELTS - December 2023

2024-01-02 Thread Sylvain Beucler
Here is my public monthly report. Thanks to our sponsors for making this possible, and to Freexian for handling the offering. https://www.freexian.com/lts/debian/#sponsors LTS - Front Desk (week 48, December half) - Mark 5 packages for update - Triage or precise triage for <10 CVEs -