Re: Bug#1135779: beets: CVE-2026-42052
"Pieter Lenaerts" <[email protected]> Sat, 09 May 2026 15:11:02 +0200
| Newsgroups | gmane.linux.debian.devel.python |
|---|---|
| Message-ID | <[email protected]> |
--4b926edb69896b8292bf1239d2e36539e20055eadf6dfba9da74801960c6 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 On Wed May 6, 2026 at 7:47 AM CEST, Salvatore Bonaccorso wrote: Hi Salvatore & python team, > [...] just uploading the fixing version to > unstable is good. I'm looking into getting the update to unstable. There are some dependency issues. > For stable and oldstable I believe it does not need > a security update, we will mark it no-dsa in the security tracker. If > you mean to fix it in stable and olstable doing it via a upcoming > point release would be sufficient. I have now pushed my proposition for a trixie update to https://salsa.debian.org/python-team/packages/beets/-/tree/debian/stable/ I backported the patch and added a test to check for unsafe input fields in= the template. 1. Can someone in the python team review my proposed fix? 2. Should this then become a stable update, following that process? If yes = I will open a stable update bug. Thanks for giving me directions, Pieter --4b926edb69896b8292bf1239d2e36539e20055eadf6dfba9da74801960c6 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iIkEABYKADEWIQQrLg4/tS9aUxZMq8oFuPKwcqDg6wUCaf8yaBMccGxlbmFlQGRp c3Jvb3Qub3JnAAoJEAW48rByoODrx9UBAPz3ksy/XfOXBOR0pB4FCi9SE3Z7QC09 GzxbUiqMS9f4AP0VxaSO8aJKLvNjk21NXwOZUs3Mii59N/7bBQIdvJdMDQ== =/9HW -----END PGP SIGNATURE----- --4b926edb69896b8292bf1239d2e36539e20055eadf6dfba9da74801960c6--