Bug#1053310: Fixes for stable/oldstable?

2023-11-01 Thread Tomas Pospisek
On Tue, 31 Oct 2023, Andreas Metzler wrote: On 2023-10-31 Tomas Pospisek wrote: [...] PS: I'd prefer this bugreport to be open as long as the stable and oldstable packages are still vulnerable... Hello Thomas, The Debian BTS does not use a simple open/close logic, it tracks which

Bug#1053310: Fixes for stable/oldstable?

2023-10-31 Thread Andreas Metzler
On 2023-10-31 Tomas Pospisek wrote: [...] > PS: I'd prefer this bugreport to be open as long as the stable and > oldstable packages are still vulnerable... Hello Thomas, The Debian BTS does not use a simple open/close logic, it tracks which specific versions a bug applies to. If you look at

Bug#1053310: Fixes for stable/oldstable?

2023-10-31 Thread Andreas Metzler
On 2023-10-31 Tomas Pospisek wrote: > On Tue, 31 Oct 2023, Salvatore Bonaccorso wrote: [...] >> Fixes for CVE-2023-42117 and CVE-2023-42119 are right now considered >> no-dsa (see comment on the security-tracker about it), and are going >> to be fixed in the next point releases. > The notes say:

Bug#1053310: Fixes for stable/oldstable?

2023-10-31 Thread Tomas Pospisek
Hi Salvatore, thanks a lot for your reply (more below): On Tue, 31 Oct 2023, Salvatore Bonaccorso wrote: Hi Tomas, On Tue, Oct 31, 2023 at 11:07:06AM +0100, Tomas Pospisek wrote: Hello Exim maintainers, this ticket, asking for packages with fixes for CVE-2023-42117 and other security

Bug#1053310: Fixes for stable/oldstable?

2023-10-31 Thread Salvatore Bonaccorso
Hi Tomas, On Tue, Oct 31, 2023 at 11:07:06AM +0100, Tomas Pospisek wrote: > Hello Exim maintainers, > > this ticket, asking for packages with fixes for CVE-2023-42117 and other > security relavant issues is closed. > > However only a package for unstable has been released: > >

Bug#1053310: Fixes for stable/oldstable?

2023-10-31 Thread Tomas Pospisek
Hello Exim maintainers, this ticket, asking for packages with fixes for CVE-2023-42117 and other security relavant issues is closed. However only a package for unstable has been released: https://security-tracker.debian.org/tracker/CVE-2023-42117 all other Debian releases (stable,