[SECURITY] [DLA 3731-1] man-db: fix sandboxing issues

2024-02-01 Thread Colin Watson
- Debian LTS Advisory DLA-3731-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Colin Watson February 01, 2024 https://wiki.debian.org/LTS

Accepted man-db 2.8.5-2+deb10u1 (source) into oldoldstable

2024-02-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Thu, 01 Feb 2024 13:35:20 + Source: man-db Architecture: source Version: 2.8.5-2+deb10u1 Distribution: buster-security Urgency: medium Maintainer: Colin Watson Changed-By: Colin Watson Closes: 926450 948238 1061870 Changes:

Debian LTS report for January 2024

2024-02-01 Thread Guilhem Moulin
During the month of January 2024 and on behalf of Freexian, I worked on the following: php-phpseclib - Uploaded 2.0.30-2~deb10u2 and issued DLA-3718-1 https://lists.debian.org/msgid-search/?m=zbhgvxygvemfp...@debian.org * CVE-2023-48795: Terrapin attack phpseclib -

Debian LTS and ELTS - January 2024

2024-02-01 Thread Sylvain Beucler
Here is my public monthly report. Thanks to our sponsors for making this possible, and to Freexian for handling the offering. https://www.freexian.com/lts/debian/#sponsors LTS - Front Desk (week 4) - Mark 1 package for update - Triage or precise triage for ~20 CVEs - Tidy golang-1.11

Re: man-db hardening fixes

2024-02-01 Thread Colin Watson
On Thu, Feb 01, 2024 at 05:41:19PM +0530, Utkarsh Gupta wrote: > On Thu, Feb 1, 2024 at 1:44 AM Colin Watson wrote: > > I'm both the Debian and upstream maintainer of man-db. I'm considering > > uploading some variation of the attached diff to buster-security LTS. > > They're adjustments to

(E)?LTS report for january

2024-02-01 Thread Bastien Roucariès
I've worked during january on the below listed packages, for Freexian LTS/ELTS [1] Many thanks to Freexian and our sponsors [2] for providing this opportunity! ELTS: tinyxml -- Fix CVE-2023-34194 and release ELA-1029-1. Note that this project is dead upstram, but a fork seems

Re: man-db hardening fixes

2024-02-01 Thread Utkarsh Gupta
Hi Colin, On Thu, Feb 1, 2024 at 1:44 AM Colin Watson wrote: > I'm both the Debian and upstream maintainer of man-db. I'm considering > uploading some variation of the attached diff to buster-security LTS. > They're adjustments to hardening arrangements, so they do have some > security