Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #210149 > unrolled thread
| Started by | Lazar Tadić <lazar.tadic34@gmail.com> |
|---|---|
| First post | 2019-06-20 19:00 +0200 |
| Last post | 2019-06-28 13:10 +0200 |
| Articles | 8 — 5 participants |
Back to article view | Back to linux.debian.user
Please consider unblocking Chromium and linux packages for Buster Lazar Tadić <lazar.tadic34@gmail.com> - 2019-06-20 19:00 +0200
Re: Please consider unblocking Chromium and linux packages for Buster Étienne Mollier <etienne.mollier@mailoo.org> - 2019-06-20 20:50 +0200
Re: Please consider unblocking Chromium and linux packages for Buster Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-20 20:50 +0200
Re: Please consider unblocking Chromium and linux packages for Buster Étienne Mollier <etienne.mollier@mailoo.org> - 2019-06-20 21:00 +0200
Re: Please consider unblocking Chromium and linux packages for Buster Sven Joachim <svenjoac@gmx.de> - 2019-06-20 21:40 +0200
Re: Please consider unblocking Chromium and linux packages for Buster Lazar Tadić <lazar.tadic34@gmail.com> - 2019-06-20 22:10 +0200
Re: Please consider unblocking Chromium and linux packages for Buster Étienne Mollier <etienne.mollier@mailoo.org> - 2019-06-20 22:50 +0200
Re: Please consider unblocking Chromium and linux packages for Buster Michael Fothergill <michael.fothergill@gmail.com> - 2019-06-28 13:10 +0200
| From | Lazar Tadić <lazar.tadic34@gmail.com> |
|---|---|
| Date | 2019-06-20 19:00 +0200 |
| Subject | Please consider unblocking Chromium and linux packages for Buster |
| Message-ID | <yb8zL-Xk-1@gated-at.bofh.it> |
Chromium is currently 2 major and 3 minor versions behind upstream in both Stretch and Buster. Please consider uploading a recent version to address 34 open security issues, before the complete freeze on 25th of June. Likewise, linux package in Buster lack recent fixes for SACKs Panic vulnerabilities. I hope it will also be uploaded soon. Regards, Lazar
[toc] | [next] | [standalone]
| From | Étienne Mollier <etienne.mollier@mailoo.org> |
|---|---|
| Date | 2019-06-20 20:50 +0200 |
| Message-ID | <ybaid-24z-1@gated-at.bofh.it> |
| In reply to | #210149 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 6/20/19 6:40 PM, Lazar Tadić wrote: > Likewise, linux package in Buster lack recent fixes for SACKs Panic vulnerabilities. I hope it will also be uploaded soon. Good Day Lazar, Thank you for your note. I do /not/ speak for the Debian kernel team, but an upgrade of Linux fixing these TCP SACK vulnerabilities are in the pipeline in Debian Sid, in Linux version 4.19.37-5. There is an unconditional ten days delay for introduction of upgrades from Sid to Testing, hence the missing security upgrade into Debian Buster at t time. Hopefully it should land on time for July, the 6th. Paradoxically, if security is a concern, Sid is preferable over Testing. Of course Debian Stable remains the best choice in that situation, if applications or hardware allow it. Kind Regards, - -- Étienne Mollier <etienne.mollier@mailoo.org> 59DA 56FE FFF3 882D -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEWrFO32O7zP+LVC+pWdpW/v/ziC0FAl0L1FEACgkQWdpW/v/z iC1lGQwAy1t8i7Tu1N+bgnsR+sLwgXYZ+NhRt7ldXpLGGrFUnBHwyl0SiJBADxli aDX5dXXhFSMxWFE+Stx2kGXNMLmjs3mtPnYLwAVDfLwl6WWpU8ozbVpYqitROq8f +7Ze7vSUu1tI8JEREYmx8kfDTNfBDyveM8UTaFQnUQuUZ/aZP7P4PBH8Jv2KKKih Ihy6gAtYv8Ah2I1rwjO6UtFh+cWsfX0wrDMz6MPmvQCJT7scPW4F45BHHS6q5C5l 7/JMrrmAFBCD394TRzSN5ry1GacQu7ayaorDy7gW7bsJPeS7ZIqTgQUWwQBMy68m yvauyGWm1lWKKoj5cEQwjFQb0WGasjIFm7J/+Dkd1at81fn3JgjvcgNf2o8zwx14 hCU5po0HlwIowC1SzoM5vQ2zf114voPqkbicxON8AVPaQoFL+vrSWOiKJNey3YAo Nls/D1Cfzn8eoTznU2qb2IRCVPybGRJizCsQ734MTYhhtZoY/5FPuh9VUmK/6YRf 8/dXXItv =H05u -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2019-06-20 20:50 +0200 |
| Message-ID | <ybaie-24z-17@gated-at.bofh.it> |
| In reply to | #210155 |
On Thu, Jun 20, 2019 at 08:45:51PM +0200, Étienne Mollier wrote: > There is an unconditional ten days delay for > introduction of upgrades from Sid to Testing, hence the missing > security upgrade into Debian Buster at t time. Hopefully it > should land on time for July, the 6th. The delay period is frequently shortened for packages with high urgency. "Unconditional ten days" is quite false. However, this is also complicated by the current freeze state of buster. Packages are not flowing by the normal rules right now. Expect everything to be a lot more manual.
[toc] | [prev] | [next] | [standalone]
| From | Étienne Mollier <etienne.mollier@mailoo.org> |
|---|---|
| Date | 2019-06-20 21:00 +0200 |
| Message-ID | <ybarT-28p-3@gated-at.bofh.it> |
| In reply to | #210158 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 6/20/19 8:48 PM, Greg Wooledge wrote: > On Thu, Jun 20, 2019 at 08:45:51PM +0200, Étienne Mollier wrote: >> There is an unconditional ten days delay for introduction of upgrades from Sid to Testing, hence the missing security upgrade into Debian Buster at t time. Hopefully it should land on time for July, the 6th. > The delay period is frequently shortened for packages with high urgency. "Unconditional ten days" is quite false. I completely missed that... Thank you Greg! :) - -- Étienne Mollier <etienne.mollier@mailoo.org> 59DA 56FE FFF3 882D -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEWrFO32O7zP+LVC+pWdpW/v/ziC0FAl0L1eAACgkQWdpW/v/z iC3DFQwAi2xBm2jj1i7ukHuvco/xCqWuPnWoKVn9yU+D8k0Fm5ksvVItF603LtNS 2xLVfmFmjg5r6ATJXxFH3KnU+6niV89ArArFovLUd3fJcrqoYBcYeRmbgLmhl7b3 Hre7JlIgi+YRtDv8RxTIEiNnaNpcJt7/UrCpwwcHN9dmUXqLFF2MfDU9mhYVlgS1 ECwGQuMeA5Nh/msdWJ7E5chzKpgJtphZsLWV5zCrqGEgB5Xl9CtdUrypT+dALrJM pSqnDP5Yp/NqOGqJWCtO8YHbwc1xWlxNijtxYlCUvc9siGSW6DHqyRFnOROXiEVY Zpt/6MTgb9el6G6HM9HemDBZ+oo5phtflMb0NwM0KKO1r4WesoL36JnUR2+9ZOrF NOOfGL/VIvBIJXrpapuc+WgWFPtdviA30unns7gZ6y9ZfHCAO5PQYTpqsAZ5Fjzn wz49/EUoMD51u69Y+BS/mZdJrJnKWneqRybcVevtYp8HNQ6LnS5I4cM9nOX7GV7g D6zCY8yM =C0hr -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Sven Joachim <svenjoac@gmx.de> |
|---|---|
| Date | 2019-06-20 21:40 +0200 |
| Message-ID | <ybb4B-2Bq-1@gated-at.bofh.it> |
| In reply to | #210158 |
On 2019-06-20 14:48 -0400, Greg Wooledge wrote:
> On Thu, Jun 20, 2019 at 08:45:51PM +0200, Étienne Mollier wrote:
>> There is an unconditional ten days delay for
>> introduction of upgrades from Sid to Testing, hence the missing
>> security upgrade into Debian Buster at t time. Hopefully it
>> should land on time for July, the 6th.
>
> The delay period is frequently shortened for packages with high urgency.
It is also frequently prolonged for packages which FTBFS on some
architecture or which are entangled in a library transition.
> "Unconditional ten days" is quite false.
For packages with high urgency it is usually two days if everything
works fine, but it can easily be two months or longer. For security
critical packages like web browsers I would always recommend getting a
newer version from unstable or from stable-security ASAP.
Cheers,
Sven
[toc] | [prev] | [next] | [standalone]
| From | Lazar Tadić <lazar.tadic34@gmail.com> |
|---|---|
| Date | 2019-06-20 22:10 +0200 |
| Subject | Re: Please consider unblocking Chromium and linux packages for Buster |
| Message-ID | <ybbxD-31o-1@gated-at.bofh.it> |
| In reply to | #210149 |
> Thank you for your note. I do /not/ speak for the Debian kernel > team, but an upgrade of Linux fixing these TCP SACK > vulnerabilities are in the pipeline in Debian Sid, in Linux > version 4.19.37-5. There is an unconditional ten days delay for > introduction of upgrades from Sid to Testing, > The delay period is frequently shortened for packages with high > urgency. > "Unconditional ten days" is quite false. > Thank you both for your replies. Indeed, the delay for important packages like linux is shorter, especially if the fix is urgent. I know that the work devs do is voluntary and I'm certain they do their best. I'll wait for the fixes to arrive in Buster naturally. I just don't want to use Chrome. It is enough that I'm using Google's services :) Oh, and please excuse me for my poor use of these mailing lists, I'm new here. Regards, Lazar
[toc] | [prev] | [next] | [standalone]
| From | Étienne Mollier <etienne.mollier@mailoo.org> |
|---|---|
| Date | 2019-06-20 22:50 +0200 |
| Message-ID | <ybcal-3eT-9@gated-at.bofh.it> |
| In reply to | #210168 |
[Multipart message — attachments visible in raw view] — view raw
> Oh, and please excuse me for my poor use of these mailing > lists, I'm new here. I apologize myself if I've make you feel a bit uncomfortable. I'm not a native English speaker, and sometimes my wording may happen to be a little bit stronger than first intended, but I try to watch my tongue. Blame the language quality in English movies! :D Security issues are enough of a concern to be welcome anyway, perhaps you can have a look at the following page, should you need to contact Debian Security team at some point: https://www.debian.org/security/faq I should have read this myself earlier: I found the two days mentioned by Greg in one of the entries relative to Testing. :) Kind Regards, -- Étienne Mollier <etienne.mollier@mailoo.org> 59DA 56FE FFF3 882D
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2019-06-28 13:10 +0200 |
| Message-ID | <ydWVr-2YD-5@gated-at.bofh.it> |
| In reply to | #210149 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, 20 Jun 2019 at 17:57, Lazar Tadić <lazar.tadic34@gmail.com> wrote: > Chromium is currently 2 major and 3 minor versions behind upstream in > both Stretch and Buster. Please consider uploading a recent version to > address 34 open security issues, before the complete freeze on 25th of > June. > I have recently installed gentoo prefix within my debian buster OS on my kaveri box. I installed chromium 76: mikef@fart:~/gentoo/etc/portage$ equery l chromium * Searching for chromium ... [IP-] [ ] www-client/chromium-76.0.3809.36:0 mikef@fart:~/gentoo/etc/portage$ It does take some effort install gentoo prefix on debian. But I have figured out how to do it with the help of the gentoo prefix dev team. I am grateful to them. Cheers Michael Fothergill > > Likewise, linux package in Buster lack recent fixes for SACKs > Panic vulnerabilities. I hope it will also be uploaded soon. > > Regards, > Lazar > >
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web