Re: CVE-2021-4034 in testing seems to be fixed but showed as vulnerable

2022-01-27 Thread Hideki Yamane
Hi Salvatore, On Thu, 27 Jan 2022 15:52:15 +0100 Salvatore Bonaccorso wrote: > Yes, I meant the upload of 0.105-31.1~deb12u1 was a temporary solution > as packages in unstable were stopped from migrating. > > policykit-1 in unstable fixes the issue as well, but got build with > the broken

CVE-2021-4034 in testing seems to be fixed but showed as vulnerable

2022-01-27 Thread Hideki Yamane
Hi, policykit-1 in testing is noted as vulnerable but its version 0.105-31.1~deb12u1 fixed CVE-2021-4034. Will the data in security-tracker be updated automatically? -- Regards, Hideki Yamane henrich @ debian.org/iijmio-mail.jp

Re: CVE-2021-4034 in testing seems to be fixed but showed as vulnerable

2022-01-27 Thread Salvatore Bonaccorso
HI, On Thu, Jan 27, 2022 at 11:03:44PM +0900, Hideki Yamane wrote: > Hi Salvatore, > > On Thu, 27 Jan 2022 14:42:21 +0100 > Salvatore Bonaccorso wrote: > > > policykit-1 in testing is noted as vulnerable but its version > > > 0.105-31.1~deb12u1 fixed CVE-2021-4034. > > > > > > Will the data

Re: CVE-2021-4034 in testing seems to be fixed but showed as vulnerable

2022-01-27 Thread Hideki Yamane
Hi Salvatore, On Thu, 27 Jan 2022 14:42:21 +0100 Salvatore Bonaccorso wrote: > > policykit-1 in testing is noted as vulnerable but its version > > 0.105-31.1~deb12u1 fixed CVE-2021-4034. > > > > Will the data in security-tracker be updated automatically? > > I'm aware of that, but I have

Re: CVE-2021-4034 in testing seems to be fixed but showed as vulnerable

2022-01-27 Thread Salvatore Bonaccorso
Hi! On Thu, Jan 27, 2022 at 08:34:32PM +0900, Hideki Yamane wrote: > Hi, > > policykit-1 in testing is noted as vulnerable but its version > 0.105-31.1~deb12u1 fixed CVE-2021-4034. > > Will the data in security-tracker be updated automatically? I'm aware of that, but I have not added a

Bug#1001451: Candidate script updates

2022-01-27 Thread Neil Williams
On Wed, 26 Jan 2022 10:10:04 +0100 Salvatore Bonaccorso wrote: > Hi Neil, > > I think, if there are no objections from other, that we can look > forward into merging the grab-cve-fixes and merge-cve-list updates.