Bug#1081907: vte: CVE-2024-37535

2024-09-27 Thread Moritz Mühlenhoff
Am Sun, Sep 15, 2024 at 11:03:42PM +0100 schrieb Simon McVittie: > On Sun, 15 Sep 2024 at 23:18:53 +0200, Moritz Mühlenhoff wrote: > > The following vulnerability was published for vte. This is already addressed > > in vte2.91, but also filing this for completeness for the deprecated source > > pac

Bug#1081907: vte: CVE-2024-37535

2024-09-27 Thread Simon McVittie
Control: tags -1 + wontfix On Fri, 27 Sep 2024 at 15:34:33 +0200, Moritz Mühlenhoff wrote: > Am Sun, Sep 15, 2024 at 11:03:42PM +0100 schrieb Simon McVittie: > > I think this is wontfix. The only reason why the GTK2-based vte is still > > in Debian at all is for the benefit of debian-installer, wh

Bug#1081907: vte: CVE-2024-37535

2024-09-15 Thread Simon McVittie
On Sun, 15 Sep 2024 at 23:18:53 +0200, Moritz Mühlenhoff wrote: > The following vulnerability was published for vte. This is already addressed > in vte2.91, but also filing this for completeness for the deprecated source > package: > > CVE-2024-37535[0]: > | GNOME VTE before 0.76.3 allows an attac

Bug#1081907: vte: CVE-2024-37535

2024-09-15 Thread Moritz Mühlenhoff
Source: vte X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for vte. This is already addressed in vte2.91, but also filing this for completeness for the deprecated source package: CVE-2024-37535[0]: | GNOME VTE before 0.76.3