Re: Adding python-django to dla-needed.txt

2021-04-08 Thread Chris Lamb
Hi Emilio, > Glancing at lts-frontdesk.2021.txt, it seems like you are on LTS duty > this week. Would you object if I added and claimed python-django to > address CVE-2021-28658? I am the maintainer in unstable. (The same > goes for ela-needed.txt too.) Gentle ping on the above? Regards, --

Re: Adding python-django to dla-needed.txt

2021-04-08 Thread Utkarsh Gupta
Hi Chris, On Thu, Apr 8, 2021 at 4:21 PM Chris Lamb wrote: > > Glancing at lts-frontdesk.2021.txt, it seems like you are on LTS duty > > this week. Would you object if I added and claimed python-django to > > address CVE-2021-28658? I am the maintainer in unstable. (The same > > goes for ela-need

Re: Best way forward for CVE-2021-22876/curl?

2021-04-08 Thread Ola Lundqvist
Hi Utkarsh, all I have done some more investigation on this matter. I have checked the statement from upstream that we can re-use some existing strip code to remove the strings this way. The thing is that I cannot find any code that do URL stripping so that is not really a viable option. This leav