• Bug#1093047: dcmtk: leftover CVE status.

    From Salvatore Bonaccorso@21:1/5 to All on Wed Feb 12 08:10:02 2025
    Hi Étienne

    On Tue, Feb 11, 2025 at 10:24:33PM +0100, Étienne Mollier wrote:
    Hi Salvatore,

    Salvatore Bonaccorso, on 2025-02-09:
    Regarding CVE-2024-28130, should we ignore it for fixing in bookworm
    if it is too risky for regressions?

    With the first batch of CVEs addressed in proposed-updates, I
    could take a fresher look at the patch set. I thought I would
    hit a brick wall, but instead I seem to have an implementation:

    * which includes the necessary upstream changes;
    * which does not cause regressions in autpkgtest of reverse
    dependencies;
    * which does not cause build failure of reverse build
    dependencies;
    * which does not regress like what could be observed in the
    bug #1095072.

    I can't really recall why I didn't manage to get anywhere
    earlier; perhaps I messed the order of the patches. My changes
    are available on Salsa[1] for those who are curious. There are
    a lot of changes introduced by the patches, so it could be still
    deemed risky, but I now think I might be able to justify them to
    the Stable Release Managers.

    [1]: https://salsa.debian.org/med-team/dcmtk/-/tree/debian/bookworm?ref_type=heads

    Have a good evening, :)

    Thanks a lot for your work, and for providing this status update. Then
    I suggest that we do not not ignore the remaining CVEs and you can
    address this equally trough the point release.

    Thanks again!

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From =?utf-8?Q?=C3=89tienne?= Mollier@21:1/5 to All on Thu Feb 13 22:50:01 2025
    Good day,

    Salvatore Bonaccorso, on 2025-02-12:
    Thanks a lot for your work, and for providing this status update. Then
    I suggest that we do not not ignore the remaining CVEs and you can
    address this equally trough the point release.

    Sounds good, I opened #1095072 to discuss the integration.

    Have a nice day, :)
    --
    .''`. Étienne Mollier <emollier@debian.org>
    : :' : pgp: 8f91 b227 c7d6 f2b1 948c 8236 793c f67e 8f0d 11da
    `. `' sent from /dev/pts/1, please excuse my verbosity
    `- on air: Triumvirat - A Day in a Life

    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCgAdFiEEj5GyJ8fW8rGUjII2eTz2fo8NEdoFAmeuZjYACgkQeTz2fo8N Edpu1BAArBZvXxdwigRMwF3kYVfCYzUkQ5ULlFFukj7jYvYd60Awdk+VISLdVb0a Nwt/gUoDNul2uhAy+zSKicMde12SS+KAxTXli7vqvKyvfMhX3bG4Njj+srEZP9uY Sh9QzH0J06ILDoERcyXtnX0AY6o8+8t0hYY9rmhRW4Iq9j1ruAnQk9E1Azpk5SMH 0h/L8kNj8J6pYDv+Z6Zdnfwb1QXJ9kLPL0xEc1jwN67ksy7HomWZggKfLaKHnWZB FBpXbtHRKEQpcEFFtZ30Qrxkdqk/ysox7cWBXASQ3pW+rGfSBgWE5LaaajRNnnt2 n8siHBeKDUuHclgyY/O8W01+hMKgVXZD9UHEYZG9O0lfWPbS0iPa8k01peZmey3M 9LIGV6ef0TMET3deEuSdAUJexVXehMbFoXE3IQdA4XSNchWey0UfyOilN3Xq9EMe 0PeqbjLeEVkL4rwwH8ztRKvGuR4w4MHMPuq/ZLkV5BNZTqtZiLQkzEyGjVS69cR+ HvmYdUlkI5Nm8wqlOOO1AZNtPpTMtHaAWjbsdQAbEdqL/IRzl9dhN+1tYVy6Rh+S vXR/yVD0zX6xlsBx+kssRT3xD7JrABSVkE7jvLu1kfAh0d7wEuKbfOggH333i116 6KUTlxFSMdkzsz7M/cM+9YkXZA5JZyG+9TTFp