Re: open security issues in the git packages

Jeremy Stanley <[email protected]>
Newsgroups gmane.linux.debian.devel.security
Message-ID <[email protected]>
On 2023-01-19 14:04:52 +0000 (+0000), Jeremy Stanley wrote:
[...]
> The only patch my colleagues and I found which needed adjustment
> was 0012, and for that I was able to apply upstream commit 3c50032
> directly instead.

Ubuntu has issued https://ubuntu.com/security/notices/USN-5810-2 now
covering the lack of completeness we alerted them to in their patch
0012 for focal and bionic, so definitely don't use their original
patch straight.
-- 
Jeremy Stanley
signature.asc (application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE-----

iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAmPJgQRfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3
QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ
WCm9QBAAh1IhgcKGT9aueYhrUwhmYM0AyvTRVGIiJlkc4PCDB8QC5HykHfQGLyQP
L1CN9BAW+tN8bKtf4/gP9J6UXLU+MmNEr0YzR1NHgz1n4GBbWKNwyjtKw4aH/kPP
vgjWANJH4emQ0MSrCOqO5bYI0NGr1QgA5ho6WWimhLvu/db1Em/ukcAfwfTUjh1f
1YNHsR4p68sXtorQTdaTergO5LAQw20DZL8YQpifoiQZqPwDNhVw0LhKHwhY0uBV
Pwkj209cL4YlvnBlpQCgp6ZbQthDlMnUo/q3YhyU2INlwdnJsg6w/P8albZ5yQvN
/huJQ2pliG8rPRersaJc+NvyUIvR0rEowa6IutLmaPlDtn1BK44Jjpxsl3yUgTXb
j0NyVQwMCfdfHPm3hKS/8X0b6NkPndIv9ua6YPFyIbAl526kzIfpHzbws1Mbb2PP
JlhEER4KQU4f34gj5t/MFa2TDGm3Ap8nSBgQsMKFpHF31smTCV+oEpQoO5dMEjWl
eJE3NHxhavq/JcseKUEuZwRRH75MNpcg0JiWW6oIWVP/o+nOnZ7TC0zcbb4/WVub
FbFFrlc8ik28eB5Eix3PW5K5VuHtvjPs/VEoY8VVwHfqIu9PFtdjEXFeoAyecvsE
mcHSLL8oF4gn0EuPm8byGy1CBja2kXMx8lGT/ilErs6OeOuya4M=
=fE2P
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.