- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Roland Gruber
- Date:
- 2022-07-05 18:42:03 UTC
- Severity:
- normal
- Tags:
[ Reason ] Stored XSS and arbitrary image read vulnerability. See https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-f2fr-cccr-583v [ Impact ] Security issue [ Tests ] Manual tests were done [ Risks ] Minimal risk, backport of latest release 7.9.1-1 [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable [ Changes ] Backport of upstream fixes of 7.9.1 version. See https://github.com/LDAPAccountManager/lam/commit/39c48502cfa61c682cfd5f0cac3e3a8a2c3c9dcf [ Other info ] Security team asked to add this to next point release. It would not justify a DSA.
Hi team, here is the debdiff for the changes. Best regards Roland
Control: tags -1 + confirmed p-u requests are always "normal" severity. (Fixed earlier.) [...] Please go ahead. Regards, Adam
[...] Apparently other issues did, as DSA-5177-1 was just released fixing the mentioned issue and some others. As the package discussed in this request was never actually uploaded, I'm going to close this request now. Regards, Adam