Package: keepalived
Version: 1:2.2.8-1
Severity: normal
X-Debbugs-Cc: michal.ar...@ultimum.io

Dear Maintainer,

Keepalived has --log-file option to allow log to the file.
This option is not available in debian package because it's
built without this option (dh_autoconfigure without --enable-log-file)
and reason is that in past there was a CVE-2018-19046 reported.

But it seems it's  now resolved as below:

https://github.com/acassen/keepalived/issues/1048

Commits fixing the original issue:

https://github.com/acassen/keepalived/commit/ac8e2ef053de273ce7a0cf0cb611e599dca4b298
https://github.com/acassen/keepalived/commit/26c8d6374db33bcfcdcd758b1282f12ceef4b94f
https://github.com/acassen/keepalived/commit/17f944144b3d9c5131569b1cc988cc90fd676671

So I think --enable-log-file can be added to configure now.

Thanks,
Michal Arbet (kevko)



-- System Information:
Debian Release: 12.5
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 
'proposed-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 6.1.0-18-amd64 (SMP w/32 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE= (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages keepalived depends on:
ii  init-system-helpers  1.65.2
ii  iproute2             6.1.0-3
ii  libc6                2.36-9+deb12u4
ii  libglib2.0-0         2.74.6-2
ii  libmnl0              1.0.4-3
ii  libnftnl11           1.2.4-2
ii  libnl-3-200          3.7.0-0.2+b1
ii  libnl-genl-3-200     3.7.0-0.2+b1
ii  libpcre2-8-0         10.42-1
pn  libsnmp40            <none>
ii  libssl3              3.0.11-1~deb12u2
ii  libsystemd0          252.22-1~deb12u1

Versions of packages keepalived recommends:
pn  ipvsadm  <none>

keepalived suggests no packages.

Reply via email to