Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1222860 > unrolled thread
| Started by | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| First post | 2024-12-05 22:30 +0100 |
| Last post | 2024-12-05 22:30 +0100 |
| Articles | 1 — 1 participant |
Back to article view | Back to linux.debian.bugs.dist
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Bug#1089071: bookworm-pu: package python3.11/3.11.2-6+deb12u5 Salvatore Bonaccorso <carnil@debian.org> - 2024-12-05 22:30 +0100
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2024-12-05 22:30 +0100 |
| Subject | Bug#1089071: bookworm-pu: package python3.11/3.11.2-6+deb12u5 |
| Message-ID | <JQrA5-e04Z-9@gated-at.bofh.it> |
Control: tags -1 - moreinfo Hi Adrian, On Wed, Dec 04, 2024 at 11:29:46PM +0200, Adrian Bunk wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm moreinfo > User: release.debian.org@packages.debian.org > Usertags: pu > X-Debbugs-Cc: security@debian.org, Matthias Klose <doko@debian.org> > > * CVE-2023-27043: Reject malformed addresses in email.parseaddr() > (Closes: #1059298) > * CVE-2024-6923: Encode newlines in headers in the email module > * CVE-2024-7592: Quadratic complexity parsing cookies with backslashes > * CVE-2024-9287: venv activation scripts did't quote paths > * CVE-2024-11168: urllib functions improperly validated bracketed hosts > > Tagged moreinfo, as question to the security team whether they want > this in -pu or as DSA. yes the point release route and batching this update together with oters seems fine, in particular given the next point release is scheduled to be in ~1 month. Regards, Salvatore
Back to top | Article view | linux.debian.bugs.dist
csiph-web