Bug#1073061: r-base: CVE-2024-27322 execution of arbitrary code

2024-06-25 Thread Dirk Eddelbuettel
On 25 June 2024 at 21:32, Moritz Mühlenhoff wrote: | Am Wed, Jun 12, 2024 at 05:00:25PM -0500 schrieb Dirk Eddelbuettel: | > | > On 12 June 2024 at 23:46, Moritz Mühlenhoff wrote: | > | Dirk Eddelbuettel wrote: | > | > Just FYI the view of R Core (upstream) and the R Foundation (I'm on the boar

Bug#1073061: r-base: CVE-2024-27322 execution of arbitrary code

2024-06-25 Thread Moritz Mühlenhoff
Am Wed, Jun 12, 2024 at 05:00:25PM -0500 schrieb Dirk Eddelbuettel: > > On 12 June 2024 at 23:46, Moritz Mühlenhoff wrote: > | Dirk Eddelbuettel wrote: > | > Just FYI the view of R Core (upstream) and the R Foundation (I'm on the > board) > | > is that this is a nothingburger. We would love for t

Bug#1073061: r-base: CVE-2024-27322 execution of arbitrary code

2024-06-12 Thread Dirk Eddelbuettel
On 12 June 2024 at 23:46, Moritz Mühlenhoff wrote: | Dirk Eddelbuettel wrote: | > Just FYI the view of R Core (upstream) and the R Foundation (I'm on the board) | > is that this is a nothingburger. We would love for the CVE to be retracted | > but nobody (among a team of volunteers) has time or

Bug#1073061: r-base: CVE-2024-27322 execution of arbitrary code

2024-06-12 Thread Moritz Mühlenhoff
Dirk Eddelbuettel wrote: > Just FYI the view of R Core (upstream) and the R Foundation (I'm on the board) > is that this is a nothingburger. We would love for the CVE to be retracted > but nobody (among a team of volunteers) has time or energy to pursue this. > > See > https://blog.r-project.org/

Bug#1073061: r-base: CVE-2024-27322 execution of arbitrary code

2024-06-12 Thread Dirk Eddelbuettel
On 12 June 2024 at 17:20, Vincent Danjean wrote: | Package: r-base | Version: 3.5.2-1 | Severity: important | Tags: security upstream | X-Debbugs-Cc: Debian Security Team | | I create this bug in order to track the fix of this CVE in pre-trixie Debian | releases. I mark it as found in buster

Bug#1073061: r-base: CVE-2024-27322 execution of arbitrary code

2024-06-12 Thread Vincent Danjean
Package: r-base Version: 3.5.2-1 Severity: important Tags: security upstream X-Debbugs-Cc: Debian Security Team I create this bug in order to track the fix of this CVE in pre-trixie Debian releases. I mark it as found in buster release, but it is also present in older releases. I will mark it a