Re: bind9 LTS

2024-04-13 Thread Sean Whitton
Hello, On Sun 14 Apr 2024 at 10:14am +08, Sean Whitton wrote: > Hello, > > On Sat 13 Apr 2024 at 10:04am +02, Ola Lundqvist wrote: > >> Do you happen to have reference to specific commits to look at? >> You seem to have that since you refer to them as too big to backport. > > Yes, here you go,

Re: bind9 LTS

2024-04-13 Thread Sean Whitton
Hello, On Sat 13 Apr 2024 at 10:04am +02, Ola Lundqvist wrote: > See the other mail thread. We risk breaking things since we go from > 9.11 to 9.16. > I think this is still worth investigating since bind9 is a well > written piece of software, > but here we need to weigh the risk of breaking

Re: bind9 LTS

2024-04-13 Thread Sean Whitton
Hello, On Sat 13 Apr 2024 at 10:04am +02, Ola Lundqvist wrote: > Do you happen to have reference to specific commits to look at? > You seem to have that since you refer to them as too big to backport. Yes, here you go, hopefully this format is helpful: * 92b4f88bc8..: Michał Kępień

Re: bind9 LTS

2024-04-13 Thread Ola Lundqvist
Hi Adrian On Sat, 13 Apr 2024 at 13:33, Adrian Bunk wrote: > > On Sun, Mar 31, 2024 at 10:12:34PM +0800, Sean Whitton wrote: > >... > > - looks like backporting the old branches is what's done in bullseye and > > bookworm; do you know of some reason we're not doing this for buster too? > >

Re: bind9 LTS

2024-04-13 Thread Adrian Bunk
On Sun, Mar 31, 2024 at 10:12:34PM +0800, Sean Whitton wrote: >... > - looks like backporting the old branches is what's done in bullseye and > bookworm; do you know of some reason we're not doing this for buster too? bind9 in buster provides shared libraries, with soversion changes in every

Re: freeimage and CVE-2019-12214

2024-04-13 Thread Ola Lundqvist
Thank you for your help! On Sat, 13 Apr 2024 at 09:56, Cyrille wrote: > > I don’t know anything about your procedures, but I don’t see why we wouldn’t… > > I would also contact NIST (or whoever is in charge of the CVE database; I > can’t remember by heart who it is) to let them know this, so

Re: bind9 LTS

2024-04-13 Thread Ola Lundqvist
Hi Sean On Sun, 31 Mar 2024 at 16:13, Sean Whitton wrote: > > Hello, > > On Sun 31 Mar 2024 at 09:51pm +08, Sean Whitton wrote: > > > I've started looking at the first vulnerability, CVE-2023-4408, and have > > some confusions/questions. > > > > The ISC website that 9.11 is EOL as of March

Re: bind9 patch or new upstream version

2024-04-13 Thread Ola Lundqvist
Hi Roberto On Sat, 13 Apr 2024 at 01:14, Roberto C. Sánchez wrote: > > Hi Ola, > > On Sat, Apr 13, 2024 at 12:49:49AM +0200, Ola Lundqvist wrote: > > Hi fellow LTS contributors > > > > Today I started on bind9 and realized one thing. In bullseye the > > security update is to release a new

Re: freeimage and CVE-2019-12214

2024-04-13 Thread Cyrille
I don’t know anything about your procedures, but I don’t see why we wouldn’t… I would also contact NIST (or whoever is in charge of the CVE database; I can’t remember by heart who it is) to let them know this, so they update the CVE’s vulnerable configurations. I’ll try to do that next week,

Re: bind9 patch or new upstream version

2024-04-13 Thread Ola Lundqvist
Hi Sean No I did not see it. I did not realize that since there were no note in dla-needed. Anyway thank you for letting med know. I'll check what you have determined already. / Ola Den lör 13 apr. 2024 01:23Sean Whitton skrev: > Hello, > > On Sat 13 Apr 2024 at 12:49am +02, Ola Lundqvist