Bug#1033341: org-mode: CVE-2023-28617

2023-06-04 Thread David Bremner
Salvatore Bonaccorso writes: > > Looking at https://security-tracker.debian.org/tracker/CVE-2023-28617 > I think we should be fine for bookworm already, correct? Yes, I think what is there makes sense, given the constraints of expressing a weird situation. d

Bug#1033341: org-mode: CVE-2023-28617

2023-06-04 Thread Salvatore Bonaccorso
Hi David, On Sun, Jun 04, 2023 at 08:34:18AM -0300, David Bremner wrote: > Nicholas D Steeves writes: > > > fixed 1033341 org/mode/9.5.2+dfsh-5 > > fixed 1033341 org-mode/9.6.6+dfsg-1~exp1 > > thanks > > Are you sure about that? It depends on emacs 28.2, which afaik has the > vulnerable org-mod

Bug#1033341: org-mode: CVE-2023-28617

2023-06-04 Thread David Bremner
Nicholas D Steeves writes: > fixed 1033341 org/mode/9.5.2+dfsh-5 > fixed 1033341 org-mode/9.6.6+dfsg-1~exp1 > thanks Are you sure about that? It depends on emacs 28.2, which afaik has the vulnerable org-mode embedded. I guess it's a question of interpretation, but the vulnerability is still ther