[Bug 1755310] Re: MIR libzstd

2021-04-23 Thread Matthias Klose
someboday already did that without touching the bug report:


** Changed in: libzstd (Ubuntu Xenial)
   Status: New => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1755310

Title:
  MIR libzstd

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libzstd/+bug/1755310/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1755310] Re: MIR libzstd

2021-04-22 Thread Steve Beattie
Ack from the Ubuntu Security team for moving libztsd into main in
xenial.

(There is a third CVE believed to be affecting libzstd/xenial as well,
CVE-2019-11922)

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-11922

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1755310

Title:
  MIR libzstd

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libzstd/+bug/1755310/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1755310] Re: MIR libzstd

2021-04-22 Thread Balint Reczey
Dpkg in xenial-proposed now depends on libzstd, but it has open CVEs:
https://ubuntu.com/security/cve?q=&package=libzstd

As I understand dpkg is not affected because it does not use the zstd
command and does not implement compression.

To not introduce CVE-2021-24031 and CVE-2021-24032 the zstd binary
package could be kept in universe like in later releases.


** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-24031

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-24032

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1755310

Title:
  MIR libzstd

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libzstd/+bug/1755310/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1755310] Re: MIR libzstd

2021-04-22 Thread Balint Reczey
** Also affects: libzstd (Ubuntu Xenial)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1755310

Title:
  MIR libzstd

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libzstd/+bug/1755310/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1755310] Re: MIR libzstd

2018-03-14 Thread Matthias Klose
that looks ok

Override component to main
libzstd 1.3.3+dfsg-2ubuntu1 in bionic: universe/misc -> main
libzstd-dev 1.3.3+dfsg-2ubuntu1 in bionic amd64: 
universe/libdevel/optional/100% -> main
libzstd-dev 1.3.3+dfsg-2ubuntu1 in bionic arm64: 
universe/libdevel/optional/100% -> main
libzstd-dev 1.3.3+dfsg-2ubuntu1 in bionic armhf: 
universe/libdevel/optional/100% -> main
libzstd-dev 1.3.3+dfsg-2ubuntu1 in bionic i386: universe/libdevel/optional/100% 
-> main
libzstd-dev 1.3.3+dfsg-2ubuntu1 in bionic ppc64el: 
universe/libdevel/optional/100% -> main
libzstd-dev 1.3.3+dfsg-2ubuntu1 in bionic s390x: 
universe/libdevel/optional/100% -> main
libzstd1 1.3.3+dfsg-2ubuntu1 in bionic amd64: universe/libs/optional/100% -> 
main
libzstd1 1.3.3+dfsg-2ubuntu1 in bionic arm64: universe/libs/optional/100% -> 
main
libzstd1 1.3.3+dfsg-2ubuntu1 in bionic armhf: universe/libs/optional/100% -> 
main
libzstd1 1.3.3+dfsg-2ubuntu1 in bionic i386: universe/libs/optional/100% -> main
libzstd1 1.3.3+dfsg-2ubuntu1 in bionic ppc64el: universe/libs/optional/100% -> 
main
libzstd1 1.3.3+dfsg-2ubuntu1 in bionic s390x: universe/libs/optional/100% -> 
main
libzstd1-dev 1.3.3+dfsg-2ubuntu1 in bionic amd64: 
universe/oldlibs/optional/100% -> main
libzstd1-dev 1.3.3+dfsg-2ubuntu1 in bionic arm64: 
universe/oldlibs/optional/100% -> main
libzstd1-dev 1.3.3+dfsg-2ubuntu1 in bionic armhf: 
universe/oldlibs/optional/100% -> main
libzstd1-dev 1.3.3+dfsg-2ubuntu1 in bionic i386: universe/oldlibs/optional/100% 
-> main
libzstd1-dev 1.3.3+dfsg-2ubuntu1 in bionic ppc64el: 
universe/oldlibs/optional/100% -> main
libzstd1-dev 1.3.3+dfsg-2ubuntu1 in bionic s390x: 
universe/oldlibs/optional/100% -> main
libzstd1-udeb 1.3.3+dfsg-2ubuntu1 in bionic amd64: 
universe/debian-installer/optional/100% -> main
libzstd1-udeb 1.3.3+dfsg-2ubuntu1 in bionic arm64: 
universe/debian-installer/optional/100% -> main
libzstd1-udeb 1.3.3+dfsg-2ubuntu1 in bionic armhf: 
universe/debian-installer/optional/100% -> main
libzstd1-udeb 1.3.3+dfsg-2ubuntu1 in bionic i386: 
universe/debian-installer/optional/100% -> main
libzstd1-udeb 1.3.3+dfsg-2ubuntu1 in bionic ppc64el: 
universe/debian-installer/optional/100% -> main
libzstd1-udeb 1.3.3+dfsg-2ubuntu1 in bionic s390x: 
universe/debian-installer/optional/100% -> main
zstd 1.3.3+dfsg-2ubuntu1 in bionic amd64: universe/utils/optional/100% -> main
zstd 1.3.3+dfsg-2ubuntu1 in bionic arm64: universe/utils/optional/100% -> main
zstd 1.3.3+dfsg-2ubuntu1 in bionic armhf: universe/utils/optional/100% -> main
zstd 1.3.3+dfsg-2ubuntu1 in bionic i386: universe/utils/optional/100% -> main
zstd 1.3.3+dfsg-2ubuntu1 in bionic ppc64el: universe/utils/optional/100% -> main
zstd 1.3.3+dfsg-2ubuntu1 in bionic s390x: universe/utils/optional/100% -> main
31 publications overridden.


** Changed in: libzstd (Ubuntu)
   Status: Confirmed => Fix Released

** Changed in: libzstd (Ubuntu)
 Assignee: MIR approval team (ubuntu-mir) => (unassigned)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1755310

Title:
  MIR libzstd

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libzstd/+bug/1755310/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1755310] Re: MIR libzstd

2018-03-12 Thread Dimitri John Ledkov
foundations-bugs subscribed

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1755310

Title:
  MIR libzstd

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libzstd/+bug/1755310/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs