FTP master
This month I accepted 361 and rejected 34 packages. The overall number of packages that got accepted was 362.
Debian LTS
This was my hundred-twelfth month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.
During my allocated time I uploaded:
- [DLA 3615-1] libcue security update for one CVE to fix an out-of-bounds array access
- [DLA 3631-1] xorg-server security update for two CVEs. These were embargoed issues related to privilege escalation
- [DLA 3633-1] gst-plugins-bad1.0 security update for three CVEs to fix possible DoS or arbitrary code execution when processing crafted media files.
- [1052361]bookworm-pu: the upload has been done and processed for the point release
- [1052363]bullseye-pu: the upload has been done and processed for the point release
Unfortunately upstream still could not resolve whether the patch for CVE-2023-42118 of libspf2 is valid, so no progress happened here.
I also continued to work on bind9 and try to understand why some tests fail.
Last but not least I did some days of frontdesk duties and took part in the LTS meeting.
Debian ELTS
This month was the sixty-third ELTS month. During my allocated time I uploaded:
- [ELA-978-1]cups update in Jessie and Stretch for two CVEs. One issue is related to missing boundary checks which might lead to code execution when using crafted postscript documents. The other issue is related to unauthorized access to recently printed documents.
- [ELA-990-1]xorg-server update in Jessie and Stretch for two CVEs. These were embargoed issues related to privilege escalation.
- [ELA-993-1]gst-plugins-bad1.0 update in Jessie and Stretch for three CVEs to fix possible DoS or arbitrary code execution when processing crafted media files.
I also continued to work on bind9 and as with the version in LTS, I try to understand why some tests fail.
Last but not least I did some days of frontdesk duties .
Debian Printing
This month I uploaded a new upstream version of:
- … rlpr
Within the context of preserving old printing packages, I adopted:
- … lprng
If you know of any other package that is also needed and still maintained by the QA team, please tell me.
I also uploaded new upstream version of packages or uploaded a package to fix one or the other issue:
- … cups
- … hannah-foo2zjs
This work is generously funded by Freexian!
Debian Mobcom
This month I uploaded a package to fix one or the other issue:
- … osmo-pcu The bug was filed by Helmut and was related to /usr-merge
Other stuff
This month I uploaded new upstream version of packages, did a source upload for the transition or uploaded it to fix one or the other issue: