Re: Vulnerability in pcs or is it in more generic code?

2022-09-09 Thread Paul Wise
On Fri, 2022-09-09 at 22:41 +0200, Ola Lundqvist wrote: > I see that I was not clear what I meant with "in general" :-) Woops, sorry for the noise :) > Here I found how the generic source code looks like: > https://rubydoc.info/gems/thin/1.3.1/Thin%2FBackends%2FUnixServer:connect > > You can

node-thenify

2022-09-09 Thread Ola Lundqvist
Hi follow LTS contributors It is this kind of question again. "Is it worth it?". We have CVE-2020-7677 on node-thenify. According to popcorn we have three installations. That is of course a lower end number since popcorn only counts the popcorn users, but anyway it indicates that the

Re: Vulnerability in pcs or is it in more generic code?

2022-09-09 Thread Ola Lundqvist
Hi Paul I see that I was not clear what I meant with "in general" :-) In the fix for pcs https://github.com/ClusterLabs/pcs/commit/de068e2066e377d1cc77edf25aed0198e4c77f7b you can see a comment that there is a change from umask(0) to umask(0x077) It was this umask(0) (in

[SECURITY] [DLA 3101-1] libxslt security update

2022-09-09 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 - - Debian LTS Advisory DLA-3101-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Emilio Pozuelo Monfort September 09, 2022

Re: Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-09 Thread Utkarsh Gupta
Hi Abhijith, On Fri, Sep 9, 2022 at 6:04 PM Abhijith PA wrote: > Can you share how autopkgtest.kali.org service setup and how > is it running. I am using https://ci.debian.net/doc/file.HACKING.html > to reproduce this. What is your rack server like and you also run any > proxy server. It's also

Re: Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-09 Thread Abhijith PA
Hello Raphael, On 07/09/22 11:10 AM, Raphael Hertzog wrote: > Hello Abhijith and the LTS team, > > in Kali we have applied the last ruby-active* security updates and this > broke the web API part of autopkgtest.kali.org. Can you share how autopkgtest.kali.org service setup and how is it

Accepted libxslt 1.1.32-2.2~deb10u2 (source) into oldstable

2022-09-09 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Fri, 09 Sep 2022 12:30:48 +0200 Source: libxslt Architecture: source Version: 1.1.32-2.2~deb10u2 Distribution: buster-security Urgency: medium Maintainer: Debian XML/SGML Group Changed-By: Emilio Pozuelo Monfort Changes: libxslt