Re: Vulnerable git in bullseye - what's the process?

2023-01-29 Thread David
On Sat, 28 Jan 2023 at 03:56, Tixy wrote: > On Fri, 2023-01-27 at 11:28 +, Brad Rogers wrote: > > On Fri, 27 Jan 2023 11:36:12 +0100 "Sijmen J. Mulder" > > wrote: > > > I was surprised to find that the recent git vulnerability hasn't yet > > > been addressed in Bullseye: > > >

Re: Vulnerable git in bullseye - what's the process?

2023-01-27 Thread Brad Rogers
On Fri, 27 Jan 2023 16:56:31 + Tixy wrote: Hello Tixy, >Does it? It links to a bug which says it's been fixed in sid. And the To be fair, the page lists more than just that; It lists the status for everything from Buster to Sid. Add that to the info given by Greg Wooledge (thank you

Re: Vulnerable git in bullseye - what's the process?

2023-01-27 Thread Greg Wooledge
On Fri, Jan 27, 2023 at 04:56:31PM +, Tixy wrote: > On Fri, 2023-01-27 at 11:28 +, Brad Rogers wrote: > > The security-tracker CVE page you cited has links to all the > > information you requested. > > Does it? It links to a bug which says it's been fixed in sid. And the > PTS shows it

Re: Vulnerable git in bullseye - what's the process?

2023-01-27 Thread Tixy
On Fri, 2023-01-27 at 11:28 +, Brad Rogers wrote: > On Fri, 27 Jan 2023 11:36:12 +0100 > "Sijmen J. Mulder" wrote: > > Hello Sijmen, > > The security-tracker CVE page you cited has links to all the > information you requested. > Does it? It links to a bug which says it's been fixed in

Re: Vulnerable git in bullseye - what's the process?

2023-01-27 Thread Brad Rogers
On Fri, 27 Jan 2023 11:36:12 +0100 "Sijmen J. Mulder" wrote: Hello Sijmen, The security-tracker CVE page you cited has links to all the information you requested. -- Regards _ "Valid sig separator is {dash}{dash}{space}" / ) "The blindingly obvious is never immediately

Re: Vulnerable git in bullseye - what's the process?

2023-01-27 Thread David
On Fri, 27 Jan 2023 at 21:36, Sijmen J. Mulder wrote: > > Hi all, > > I was surprised to find that the recent git vulnerability hasn't yet > been addressed in Bullseye: Hi. More info here: https://www.debian.org/security/faq and here: https://security-tracker.debian.org/tracker/ Re git, it

Vulnerable git in bullseye - what's the process?

2023-01-27 Thread Sijmen J. Mulder
Hi all, I was surprised to find that the recent git vulnerability hasn't yet been addressed in Bullseye: https://security-tracker.debian.org/tracker/CVE-2022-41903 My question isn't about the situation of this package per se but about the process. I found this diagram: