Bug#968833: [Pkg-nagios-devel] Bug#968833: CVE-2020-24368

2020-08-23 Thread Moritz Mühlenhoff
On Sat, Aug 22, 2020 at 04:37:16PM +0200, Sebastiaan Couwenberg wrote:
> On 8/22/20 4:26 PM, Moritz Muehlenhoff wrote:
> > On Sat, Aug 22, 2020 at 07:58:34AM +0200, Sebastiaan Couwenberg wrote:
> >> Hi Moritz,
> >>
> >> This is fixed in icingaweb2 (2.8.2-1) which was just uploaded to unstable.
> >>
> >> I've also prepared an update for buster, see:
> >>
> >>  https://salsa.debian.org/nagios-team/pkg-icingaweb2/-/commits/buster
> >>
> >> Do you want to upload that to security-master or shall I?
> > 
> > Thanks, looks good! Please upload to security-master (security-master
> > and ftp-master have separate dak installs and since this is the first
> > DSA for icingaweb2 in buster it needs to be built with -sa to include
> > the orig tarball)
> 
> Already did that this morning per Dev Ref 5.8.5.
> 
> Just uploaded it to security-master.

Thanks! DSA 4747 has just been released

Cheers,
Moritz



Bug#968833: [Pkg-nagios-devel] Bug#968833: CVE-2020-24368

2020-08-22 Thread Sebastiaan Couwenberg
On 8/22/20 4:26 PM, Moritz Muehlenhoff wrote:
> On Sat, Aug 22, 2020 at 07:58:34AM +0200, Sebastiaan Couwenberg wrote:
>> Hi Moritz,
>>
>> This is fixed in icingaweb2 (2.8.2-1) which was just uploaded to unstable.
>>
>> I've also prepared an update for buster, see:
>>
>>  https://salsa.debian.org/nagios-team/pkg-icingaweb2/-/commits/buster
>>
>> Do you want to upload that to security-master or shall I?
> 
> Thanks, looks good! Please upload to security-master (security-master
> and ftp-master have separate dak installs and since this is the first
> DSA for icingaweb2 in buster it needs to be built with -sa to include
> the orig tarball)

Already did that this morning per Dev Ref 5.8.5.

Just uploaded it to security-master.

Kind Regards,

Bas

-- 
 GPG Key ID: 4096R/6750F10AE88D4AF1
Fingerprint: 8182 DE41 7056 408D 6146  50D1 6750 F10A E88D 4AF1



Bug#968833: [Pkg-nagios-devel] Bug#968833: CVE-2020-24368

2020-08-22 Thread Moritz Muehlenhoff
On Sat, Aug 22, 2020 at 07:58:34AM +0200, Sebastiaan Couwenberg wrote:
> Control: tags -1 pending
> 
> Hi Moritz,
> 
> This is fixed in icingaweb2 (2.8.2-1) which was just uploaded to unstable.
> 
> I've also prepared an update for buster, see:
> 
>  https://salsa.debian.org/nagios-team/pkg-icingaweb2/-/commits/buster
> 
> Do you want to upload that to security-master or shall I?

Thanks, looks good! Please upload to security-master (security-master
and ftp-master have separate dak installs and since this is the first
DSA for icingaweb2 in buster it needs to be built with -sa to include
the orig tarball)

Cheers,
Moritz



Bug#968833: [Pkg-nagios-devel] Bug#968833: CVE-2020-24368

2020-08-22 Thread Sebastiaan Couwenberg
Control: tags -1 pending

Hi Moritz,

This is fixed in icingaweb2 (2.8.2-1) which was just uploaded to unstable.

I've also prepared an update for buster, see:

 https://salsa.debian.org/nagios-team/pkg-icingaweb2/-/commits/buster

Do you want to upload that to security-master or shall I?

Kind Regards,

Bas

-- 
 GPG Key ID: 4096R/6750F10AE88D4AF1
Fingerprint: 8182 DE41 7056 408D 6146  50D1 6750 F10A E88D 4AF1