Bug#1087883: gh: CVE-2024-52308

2024-12-30 Thread Moritz Mühlenhoff
On Mon, Dec 30, 2024 at 03:00:40PM +0100, Santiago Vila wrote: > Hi. > > I've just made a team upload which fixes this in unstable. > > Is this the kind of security issue which deserves a DSA + upload for security, > or should we handle this using stable-proposed-updates? > > (In the first case:

Bug#1087883: gh: CVE-2024-52308

2024-12-30 Thread Santiago Vila
Hi. I've just made a team upload which fixes this in unstable. Is this the kind of security issue which deserves a DSA + upload for security, or should we handle this using stable-proposed-updates? (In the first case: Can we still help by preparing an upload without uploading it?) Thanks.

Bug#1087883: gh: CVE-2024-52308

2024-11-19 Thread Salvatore Bonaccorso
Source: gh Version: 2.46.0-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for gh. CVE-2024-52308[0]: | The GitHub CLI version 2.6.1 and earlier are vulnerable to remo