Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1016611

Bug#962067: buster-pu: package dbus/1.12.20-0+deb10u1

From "Adam D. Barratt" <adam@adam-barratt.org.uk>
Newsgroups linux.debian.bugs.dist, linux.debian.maint.boot, linux.debian.devel.release
Subject Bug#962067: buster-pu: package dbus/1.12.20-0+deb10u1
Date 2020-07-05 16:30 +0200
Message-ID <ApdES-80v-5@gated-at.bofh.it> (permalink)
References (1 earlier) <AdlHP-r4-1@gated-at.bofh.it> <AjRlD-3kK-1@gated-at.bofh.it> <ApbWp-6Vx-3@gated-at.bofh.it> <AdlHP-r4-1@gated-at.bofh.it> <ApbWp-6Vx-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 3 groups.

Show all headers | View raw


On Sun, 2020-07-05 at 13:24 +0100, Simon McVittie wrote:
> Control: retitle -1 buster-pu: package dbus/1.12.20-0+deb10u1
> 
> On Sat, 20 Jun 2020 at 20:26:24 +0100, Adam D. Barratt wrote:
> > On Tue, 2020-06-02 at 21:22 +0100, Simon McVittie wrote:
> > > dbus 1.12.18 fixes a local denial of service vulnerability for
> > > which the Security Team have indicated they do not intend to
> > > issue a DSA.
> > > 
> > > If possible I would like to use upstream 1.12.x versions of dbus
> > > for buster (security and) stable updates, similar to the policy
> > > used in stretch and jessie. This branch includes security fixes
> > > and selected non-intrusive bug fixes (and unfortunately also the
> > > usual Autotools noise).
> > > 
> > 
> > That sounds OK to me, but will need the usual KiBi-ack due to the
> > udeb.
> 
> I have now released 1.12.20 upstream. This fixes a long-standing
> use-after-free if two usernames have the same numeric uid (which is
> potentially a security fix if you have such usernames), and a
> regression on Solaris derivatives. Does this still look OK for
> buster-pu? (Diff since the version you already saw attached - I
> haven't bothered to filter out the Autotools noise this time, because
> there is much less of it.)

I'd be OK with that from the SRM side (with the remaining d-i caveat).

> I've asked the security team whether they will now want a DSA for the
> use-after-free, but I suspect the answer will be "no, talk to the
> stable release team" so I'm asking preemptively.
> 
> For #962068, dbus 1.10.30 -> 1.10.32 has a remarkably similar diff
> (it's a cherry-pick of the same commits as in 1.12.20). I assume the
> judgement on that from both the security team and the stable release
> team will be the same as for buster, unless the stretch EOL has
> already happened by the time we get there.

My understanding is that security support for stretch ended yesterday.
(We've ended up with an extra week for fixes via opu due to
availability of people for the point release.)

Regards,

Adam

Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#962067: buster-pu: package dbus/1.12.18-0+deb10u1 Simon McVittie <smcv@debian.org> - 2020-06-02 22:30 +0200
  Bug#962067: buster-pu: package dbus/1.12.18-0+deb10u1 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2020-06-20 21:40 +0200
    Bug#962067: buster-pu: package dbus/1.12.20-0+deb10u1 Simon McVittie <smcv@debian.org> - 2020-07-05 14:30 +0200
      Bug#962067: buster-pu: package dbus/1.12.20-0+deb10u1 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2020-07-05 16:30 +0200
        Bug#962067: buster-pu: package dbus/1.12.20-0+deb10u1 Cyril Brulebois <kibi@debian.org> - 2020-07-11 15:10 +0200
  Bug#962067: dbus 1.12.20-0+deb10u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2020-07-11 17:40 +0200

csiph-web