Re: Jessie update of libpam-krb5?

2020-03-31 Thread Russ Allbery
Mike Gabriel writes: > On Di 31 Mär 2020 10:28:42 CEST, Mike Gabriel wrote: >> PS: A member of the LTS team might start working on this update at >> any point in time. You can verify whether someone is registered >> on this update in this file: >> https://salsa.debian.org/security-tracker-team/s

Re: CVE-2020-10648 in u-boot

2020-03-31 Thread Holger Levsen
hi, looping the u-boot maintainer in... what's your opinion on this, Vagrant? On Tue, Mar 31, 2020 at 10:46:58PM +0200, Ola Lundqvist wrote: > I would like to have some advice about the u-boot triaging. > The problem is that someone can load an alternative configuration file > and by that boot ar

CVE-2020-10648 in u-boot

2020-03-31 Thread Ola Lundqvist
Hi I would like to have some advice about the u-boot triaging. The problem is that someone can load an alternative configuration file and by that boot arbitrary code. I assume this means that the attacker must have physical access to the device. As I see it, this can be used to root devices that

Re: Jessie update of libpam-krb5?

2020-03-31 Thread Mike Gabriel
Hi Russ, hi Sam, On Di 31 Mär 2020 10:28:42 CEST, Mike Gabriel wrote: PS: A member of the LTS team might start working on this update at any point in time. You can verify whether someone is registered on this update in this file: https://salsa.debian.org/security-tracker-team/security-tracker/

Jessie update of libpam-krb5?

2020-03-31 Thread Mike Gabriel
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Jessie version of libpam-krb5: https://security-tracker.debian.org/tracker/source-package/libpam-krb5 Would you like to take care of this yourself? If yes, please follow the workflow we