Bug#972903: buster-pu: package node-pathval/1.1.0-3+deb10u1

2020-10-25 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu [ Reason ] node-pathval is vulnerable to a prototype pollution (CVE-2020-7751, #972895) [ Impact ] Little security risk [ Tests ] The same patch is applied to debian/sid (same vers

Bug#972651: buster-pu: package fastd/18-3+deb10u1

2020-10-25 Thread Sven Eckelmann
On Saturday, 24 October 2020 20:37:36 CET Adam D. Barratt wrote: > Please go ahead. Thanks, uploaded [1] with appended CVE in the changelog. Kind regards, Sven [1] https://release.debian.org/proposed-updates/buster_diffs/fastd_18-3+deb10u1.debdiff signature.asc Description: This is a d

Processed: Re: Raising severities

2020-10-25 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > unblock 972176 by 972163 972166 Bug #972176 [src:shotcut] shotcut: FTBFS with Qt 5.15: error: aggregate 'QPainterPath histPath' has incomplete type and cannot be defined 972176 was blocked by: 972163 972166 972176 was blocking: 972278 Removed blo

Re: [Pkg-mozext-maintainers] Updating Mozilla plugins in stable

2020-10-25 Thread Carsten Schoenert
Hello Mehtilde, Am 25.10.20 um 13:39 schrieb Mechtilde Stehmann: >> On a related note, britney isn't attempting to migrate the 2.18 upload >> because: >> >> Not built on buildd: arch all binaries uploaded by o...@mechtilde.de, a new >> source-only upload is needed to allow migration > > Do you m

Re: [Pkg-mozext-maintainers] Updating Mozilla plugins in stable (was: Re: Bug#971807: buster-pu: package webext-tbsync)

2020-10-25 Thread Mechtilde Stehmann
Hallo Adam Am 24.10.20 um 18:00 schrieb Adam D. Barratt: > > So should we be expecting further p-u uploads for 2.18? packages are uploaded. > > On a related note, britney isn't attempting to migrate the 2.18 upload > because: > > Not built on buildd: arch all binaries uploaded by o...@mechtil

Bug#971277: dpdk 18.11.10-1~deb10u1 flagged for acceptance

2020-10-25 Thread Luca Boccassi
On Sat, 24 Oct 2020 at 18:38, Adam D. Barratt wrote: > > On Fri, 2020-10-16 at 17:05 +, Adam D Barratt wrote: > > Package: dpdk > > Version: 18.11.10-1~deb10u1 > > > > Explanation: new upstream stable release; fix remote code execution > > issue [CVE-2020-14374], TOCTOU issues [CVE-2020-14375]