Re: Bug#1135779: beets: CVE-2026-42052

"Pieter Lenaerts" <[email protected]> Sat, 09 May 2026 15:11:02 +0200
Newsgroups gmane.linux.debian.devel.python
Message-ID <[email protected]>
--4b926edb69896b8292bf1239d2e36539e20055eadf6dfba9da74801960c6
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset=UTF-8

On Wed May 6, 2026 at 7:47 AM CEST, Salvatore Bonaccorso wrote:

Hi Salvatore & python team,


> [...] just uploading the fixing version to
> unstable is good.

I'm looking into getting the update to unstable. There are some dependency
issues.

> For stable and oldstable I believe it does not need
> a security update, we will mark it no-dsa in the security tracker. If
> you mean to fix it in stable and olstable doing it via a upcoming
> point release would be sufficient.

I have now pushed my proposition for a trixie update to
https://salsa.debian.org/python-team/packages/beets/-/tree/debian/stable/

I backported the patch and added a test to check for unsafe input fields in=
 the
template.

1. Can someone in the python team review my proposed fix?
2. Should this then become a stable update, following that process? If yes =
I
will open a stable update bug.

Thanks for giving me directions,

Pieter

--4b926edb69896b8292bf1239d2e36539e20055eadf6dfba9da74801960c6
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iIkEABYKADEWIQQrLg4/tS9aUxZMq8oFuPKwcqDg6wUCaf8yaBMccGxlbmFlQGRp
c3Jvb3Qub3JnAAoJEAW48rByoODrx9UBAPz3ksy/XfOXBOR0pB4FCi9SE3Z7QC09
GzxbUiqMS9f4AP0VxaSO8aJKLvNjk21NXwOZUs3Mii59N/7bBQIdvJdMDQ==
=/9HW
-----END PGP SIGNATURE-----

--4b926edb69896b8292bf1239d2e36539e20055eadf6dfba9da74801960c6--