Bug#913801: stretch-pu: package mistral/3.0.0-4 CVE-2018-16849: std.ssh action may disclose presence of arbitrary files

2018-12-03 Thread Thomas Goirand
On 12/3/18 8:17 AM, Julien Cristau wrote: > Control: tag -1 confirmed > > On Thu, Nov 15, 2018 at 02:07:01PM +0100, Thomas Goirand wrote: >> diff --git a/debian/changelog b/debian/changelog >> index b2ce8602..06234034 100644 >> --- a/debian/changelog >> +++ b/debian/changelog >> @@ -1,3 +1,11 @@

Processed: Re: Bug#913801: stretch-pu: package mistral/3.0.0-4 CVE-2018-16849: std.ssh action may disclose presence of arbitrary files

2018-12-02 Thread Debian Bug Tracking System
Processing control commands: > tag -1 confirmed Bug #913801 [release.debian.org] stretch-pu: package mistral/3.0.0-4 CVE-2018-16849: std.ssh action may disclose presence of arbitrary files Added tag(s) confirmed. -- 913801: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=913801 Debian

Bug#913801: stretch-pu: package mistral/3.0.0-4 CVE-2018-16849: std.ssh action may disclose presence of arbitrary files

2018-12-02 Thread Julien Cristau
Control: tag -1 confirmed On Thu, Nov 15, 2018 at 02:07:01PM +0100, Thomas Goirand wrote: > diff --git a/debian/changelog b/debian/changelog > index b2ce8602..06234034 100644 > --- a/debian/changelog > +++ b/debian/changelog > @@ -1,3 +1,11 @@ > +mistral (3.0.0-4+deb9u1) stretch-security;

Bug#913801: stretch-pu: package mistral/3.0.0-4 CVE-2018-16849: std.ssh action may disclose presence of arbitrary files

2018-11-15 Thread Thomas Goirand
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Dear release team, The security team doesn't wish to do a DSA for this CVE, and asked me to deal with it with the release team. Here's the CVE description: CVE-2018-16849: