[Pkg-salt-team] salt security update

Salvatore Bonaccorso carnil at debian.org
Thu Mar 15 21:50:44 UTC 2018


Hi Benjamin, hi Ondrej,

On Thu, Mar 15, 2018 at 08:19:38PM +0100, Benjamin Drung wrote:
> Hi Moritz,
> 
> Am Dienstag, den 28.11.2017, 20:53 +0100 schrieb Moritz Muehlenhoff:
> > Hi Benjamin,
> > can you please prepare a security update for CVE-2017-14695 /
> > CVE-2017-14696 / CVE-2017-12791 / CVE-2017-8109 in salt?
> > 
> > See https://security-tracker.debian.org/tracker/source-package/salt
> > for references.
> 
> salt 2016.11.2+ds-1+deb9u1 addresses all except CVE-2017-8109. Ondřej,
> do you have time to take care for that CVE?

This one is marked as well as no-dsa, can you adress this one as well
via a point release?

Think the same would hold by now as well for all the remaining jessie
issues, but leaving that for confirmation to Moritz.

Regards,
Salvatore



More information about the pkg-salt-team mailing list