Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm?

2024-05-24 Thread John Waffle
7;d have to look in the notes to know for sure? Thanks, - J On Wed, May 22, 2024 at 9:56 AM John Waffle wrote: > Hello, > > I got a response from trivy, > https://github.com/aquasecurity/trivy/discussions/6722#discussioncomment-9518531 > > > Helllo @superlazyname <https:/

Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm?

2024-05-22 Thread John Waffle
any sample code / script snippets you can share with me? Maybe I can submit a PR? Maybe there is some way for trivy to notice that the issue is "ignored" and then, for only Debian, interpret that as not_affected. - John On Sat, May 18, 2024 at 5:03 AM Salvatore Bonaccorso wrote: > H

Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm?

2024-05-17 Thread John Waffle
This report came from a free tool, trivy, I filed a Github discussion about it here: https://github.com/aquasecurity/trivy/discussions/6722 On Fri, May 17, 2024 at 12:08 PM Salvatore Bonaccorso wrote: > Hi, > > On Fri, May 17, 2024 at 10:43:26AM -0400, John Waffle wrote: > >

Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm?

2024-05-17 Thread John Waffle
Hi Mark, How do I get in contact with them, should I just send a message to secur...@debian.org? Thanks, - J On Fri, May 17, 2024 at 10:54 AM Mark Brown wrote: > On Fri, May 17, 2024 at 10:43:26AM -0400, John Waffle wrote: > > > - The zlib package page https://tracker.debian.org/p

Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm?

2024-05-17 Thread John Waffle
Package: zlib Version: 1:1.2.13.dfsg-1 Related bug reports: - https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054290 - https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1056718 These were marked as resolved but it seems like I'm getting some contradictory information. - The zlib package page