[Pkg-salt-team] Bug#959684: [CVEHelp at saltstack.com] Action Required: SaltStack CVE Follow-Up Patch

Elimar Riesebieter riesebie at lxtec.de
Thu May 7 16:03:07 BST 2020


Hi Salvatore and others,

* Salvatore Bonaccorso <carnil at debian.org> [2020-05-06 13:09 +0200]:

> Hi Elimar,
> 
> On Wed, May 06, 2020 at 10:36:42AM +0200, Elimar Riesebieter wrote:
> > Hi all,
> > 
> > please notice the attached note from saltstack! I assume this is not
> > integrated into DSA 4676-1, isn't it?
> 
> Yes this is right, those parts were missing. 
> 
> Do you have possibility to test updated salt packages for stretch?

we fired up your kindly provided deb9u4 packages and run the
verification script http://em.saltstack.com/F1sH900oN0P0M17U000Qhf7
with the following result:

CVE-2020-11651 - OK
CVE-2020-11652 - OK

Thanks for cooperation
Elimar
-- 
  Never make anything simple and efficient when a way
  can be found to make it complex and wonderful ;-)



More information about the pkg-salt-team mailing list