Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1148991

Bug#1037056: bookworm-pu: package libreswan/4.10-2+deb12u1

From "Adam D. Barratt" <adam@adam-barratt.org.uk>
Newsgroups linux.debian.bugs.dist, linux.debian.devel.release
Subject Bug#1037056: bookworm-pu: package libreswan/4.10-2+deb12u1
Date 2023-06-07 18:20 +0200
Message-ID <GE437-ejGh-3@gated-at.bofh.it> (permalink)
References <GClUt-deDm-1@gated-at.bofh.it> <GClUt-deDm-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


On Fri, 2023-06-02 at 18:54 -0400, Daniel Kahn Gillmor wrote:
> Uploading libreswan 4.19-1+deb12u1 should address #1035542 (aka
> CVE-2023-30570), which addresses a potential DoS against libreswan
> instances that use a certain IKEv1 configuration.
> 
> Discussion with Salvatore Bonaccorso over in #1035542 concluded that
> using point releases for this should be sufficient.
> 

fwiw, because you already uploaded this, it hit testing-proposed-
updates, where it got autobuilt without any review from the Release
Team (as the approval boundary there is tpu -> testing, rather than
stable-new -> pu).

Hopefully that shouldn't make any practical difference, I'm just
mentioning it in case it was unexpected. (It will also need a bit of
handholding to get our tooling to recognise it properly once the
release has happened, but it's not the only package in that situation.)

Regards,

Adam

Back to linux.debian.bugs.dist | Previous | Next | Find similar | Unroll thread


Thread

Bug#1037056: bookworm-pu: package libreswan/4.10-2+deb12u1 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2023-06-07 18:20 +0200

csiph-web