Re: open security issues in the git packages

Jeremy Stanley <[email protected]>
Newsgroups gmane.linux.debian.devel.security
Message-ID <[email protected]>
On 2023-01-18 23:34:37 +0000 (UTC), Thorsten Glaser wrote:
[...]
> The versions in Debian and *buntu don’t exactly match, but perhaps
> appropriate patches for the respective versions are available, or
> they apply with little fuzz?
[...]

Just a data point around this, I spent a good chunk of yesterday
porting Ubuntu's 22-patch series for CVE-2022-23521 and
CVE-2022-41903 from the 1:2.25.1-1ubuntu3.7 package in focal-updates
to the 1:2.30.2-1 in bullseye. The only patch my colleagues and I
found which needed adjustment was 0012, and for that I was able to
apply upstream commit 3c50032 directly instead.
-- 
Jeremy Stanley
signature.asc (application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE-----

iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAmPJTf5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3
QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ
WCmaXw//bOBmYOnzNaOlJ5pMyQyA61wX9g5YNUeKR/hcW0t29rR92CQfSVNWvipo
dgQBSRfCsLgRxzAvSTws0G6aa2UaV95jqXsBdsh0KIiBzOw7HPcOtpmAkQp3jIJr
pTuVFDGFtohkU/aAX7ga3vx52l0lmduv7GSeknW/LekecH9JtTGWwqwuCJ9dxvMg
G0OYvVLim8XSqhZ0vlYrFd39s9I4a6SVk7TawdImEEIrYV0GhquQARMrohgpW11z
qPNg8U4wzNGLQvGuBzcPOzv1UD4CrapL9JSmU+RkILrcJaiETZTIoDMxrO3tvL9y
xHEq1Gh1oHMl2ZxkwdcNFr2FgMUH/t2WNLbQMuWcCt6W6N+/k+KXUpEOKrPvHDAu
6Kq4DYY633eTIFeadOadqEDnsdzeIf6PMY8KFtN7g2+TYBa1jN5+Y4mCQvCH5/zJ
yBvy0u5dzRQK+F42U+tQbRSHQNjrs2bbuIGN4kzwMEJM097SXcoTk1uncl55vD1J
OvZs4a56Ei7KU+ewI/zjNpKUBa4xY/BHQ7hqbJnCNXnunGSoR7xAKTwqXnN2H4WA
sxgixKD9Rqymm+vqe6faTFgo7ZW+y9MnwcPlqtK1KZ0lxpmqBBo6C3+JNZjQJw6f
ehJCwsZGyehgeXJCsn8PC3tfSztUD+TUKn8Q+7rFmHhaR8l3fyA=
=wRsy
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.