#1010531 bullseye-pu: package ldap-account-manager/7.4-1

#1010531#5
Date:
2022-05-03 18:18:37 UTC
From:
To:
[ Reason ]
Stored XSS and arbitrary image read vulnerability.
See https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-f2fr-cccr-583v

[ Impact ]
Security issue

[ Tests ]
Manual tests were done

[ Risks ]
Minimal risk, backport of latest release 7.9.1-1

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
Backport of upstream fixes of 7.9.1 version. See https://github.com/LDAPAccountManager/lam/commit/39c48502cfa61c682cfd5f0cac3e3a8a2c3c9dcf

[ Other info ]
Security team asked to add this to next point release. It would not justify a DSA.

#1010531#10
Date:
2022-05-03 18:22:32 UTC
From:
To:
Hi team,

here is the debdiff for the changes.


Best regards

Roland

#1010531#17
Date:
2022-05-28 19:11:14 UTC
From:
To:
Control: tags -1 + confirmed

p-u requests are always "normal" severity. (Fixed earlier.)

[...]

Please go ahead.

Regards,

Adam

#1010531#24
Date:
2022-07-05 18:37:31 UTC
From:
To:
[...]

Apparently other issues did, as DSA-5177-1 was just released fixing the
mentioned issue and some others.

As the package discussed in this request was never actually uploaded,
I'm going to close this request now.

Regards,

Adam