curl: CVE-2023-28322 and CVE-2023-27534

2023-12-18 Thread Samuel Henrique
ure and there's a lower risk of carrying a low-profile bug. That being said, feel free to go ahead if you still prefer to use the original version of the function. I have sent the debdiffs for the fixes for bullseye and bookworm (for their respective affected CVEs) to the security team and I'm waiting on their ack. Thank you, -- Samuel Henrique

curl: CVE-2023-28322 and CVE-2023-27534

2023-12-16 Thread Samuel Henrique
ases, fix the ldap issue (#1057855) on unstable, and then come back to CVE-2023-27534 and CVE-2023-28322 (to be more confident on what to do). I appreciate the reach out. Thank you, -- Samuel Henrique

Pkg sponsorship needed with LTS upload: curl/7.64.0-4+deb10u8

2023-12-16 Thread Samuel Henrique
and > you can find it at: > https://salsa.debian.org/debian/curl/-/commit/3a88731d4a68a2c3a21d1c6745f4795c2f734140 > > Feel free to make modifications or revise the commit if you find it necessary. Awesome, thank you. -- Samuel Henrique

Pkg sponsorship needed with LTS upload: curl/7.64.0-4+deb10u8

2023-12-16 Thread Samuel Henrique
o there shall soon be a new upload on buster. Thank you for helping, -- Samuel Henrique

Re: Closing of buster-backports?

2023-03-30 Thread Samuel Henrique
in 99% of the cases. -- Samuel Henrique

Re: ieee-data: are you interested in fixing a non-security related issue?

2021-06-20 Thread Samuel Henrique
> Hopefully, you meant "stretch-security". :) Hahaha, yes, I knew I should have copy-pasted to the email. > Anyway, thank you! Everything looks fine, I'll take care of the paperwork. Thanks, -- Samuel Henrique

Re: ieee-data: are you interested in fixing a non-security related issue?

2021-06-20 Thread Samuel Henrique
uot;20160613.1+deb9u1 security-master" as per Utkarsh's request on pvt. The package has been uploaded to security-master and I pushed the changes to salsa: https://salsa.debian.org/debian/ieee-data/-/tree/debian/stretch Thanks, -- Samuel Henrique

Re: ieee-data: are you interested in fixing a non-security related issue?

2021-06-06 Thread Samuel Henrique
the impact/blast radius is well contained) and there were at least 3 people interested on it (who interacted with the bug reports). Thanks, -- Samuel Henrique

ieee-data: are you interested in fixing a non-security related issue?

2021-06-05 Thread Samuel Henrique
. -- Samuel Henrique