Re: Best way forward for CVE-2021-22876/curl?

2021-05-15 Thread Sylvain Beucler
Hi Ola, You can check the LTS version at: https://www.beuc.net/tmp/debian-lts/curl/ I followed the method from Ubuntu and SUSE and backported the URL API for LTS and ELTS, plus the new test case for the CVE. I'm currently diffing the test suite results, cf. my notes at:

Re: Best way forward for CVE-2021-22876/curl?

2021-05-15 Thread Ola Lundqvist
Hi Sylvain Great! Let me know if you want help with review, testing or something else. // Ola On Sat, 15 May 2021 at 23:18, Sylvain Beucler wrote: > Hi, > > I claimed it yesterday and my work is mostly done. > > Cheers! > Sylvain > > On 15/05/2021 23:11, Ola Lundqvist wrote: > > Hi Utkarsh >

Re: Best way forward for CVE-2021-22876/curl?

2021-05-15 Thread Sylvain Beucler
Hi, I claimed it yesterday and my work is mostly done. Cheers! Sylvain On 15/05/2021 23:11, Ola Lundqvist wrote: Hi Utkarsh I have looked into your patch and I think it looks good. I do not fully understand why all the changes in url.c were done but I think it looks fine anyway. The risk

Re: Best way forward for CVE-2021-22876/curl?

2021-05-15 Thread Ola Lundqvist
Hi Utkarsh I have looked into your patch and I think it looks good. I do not fully understand why all the changes in url.c were done but I think it looks fine anyway. The risk of regression should be small. Do you want me to do the update, or do you want to do it yourself? Or do you think we

Upgrade problems from LTS -> LTS+1

2021-05-15 Thread Utkarsh Gupta
Hello, There's #988289 reported against htmldoc which is the unfortunate result of issuing a DLA when jessie was LTS and was marked as no-dsa for stretch *and* both had the same version. Whilst I'll fix this for stretch (already sponsored the upload for buster), there are more such bugs for

[SECURITY] [DLA 2662-1] postgresql-9.6 security update

2021-05-15 Thread Utkarsh Gupta
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 - --- Debian LTS Advisory DLA-2662-1 debian-...@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta May 15, 2021