Bug#876630: jessie-pu: package db5.3/5.3.28-9+deb8u1

2017-11-19 Thread Adam D. Barratt
Control: tags -1 + pending On Sat, 2017-11-18 at 21:09 +0100, Salvatore Bonaccorso wrote: > Hi Adam, > > On Sat, Nov 18, 2017 at 06:58:28PM +, Adam D. Barratt wrote: > > Control: tags -1 + confirmed > > > > On Sun, 2017-09-24 at 10:08 +0200, Salvatore Bonaccorso wrote: > > > db5.3

Bug#876630: jessie-pu: package db5.3/5.3.28-9+deb8u1

2017-11-18 Thread Salvatore Bonaccorso
Hi Adam, On Sat, Nov 18, 2017 at 06:58:28PM +, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Sun, 2017-09-24 at 10:08 +0200, Salvatore Bonaccorso wrote: > > db5.3 (5.3.28-9+deb8u1) jessie; urgency=medium > > > > > >  * Non-maintainer upload. > > >  * CVE-2017-10140: Reads

Bug#876630: jessie-pu: package db5.3/5.3.28-9+deb8u1

2017-11-18 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2017-09-24 at 10:08 +0200, Salvatore Bonaccorso wrote: > db5.3 (5.3.28-9+deb8u1) jessie; urgency=medium > > > >  * Non-maintainer upload. > >  * CVE-2017-10140: Reads DB_CONFIG from the current working > > directory. > >    Do not access DB_CONFIG when

Bug#876630: jessie-pu: package db5.3/5.3.28-9+deb8u1

2017-09-24 Thread Salvatore Bonaccorso
Package: release.debian.org Severity: normal Tags: jessie User: release.debian@packages.debian.org Usertags: pu Hi stable release managers, db5.3 in jessie is affected by the CVE-2017-10140 ("Berkeley DB reads DB_CONFIG from cwd)", #872436. The NMU to unstable back on end of august has not