Debian Bug report logs -
#987494
buster-pu: package fluidsynth/1.1.11-1+deb10u1
Reported by: Utkarsh Gupta <utkarsh@debian.org>
Date: Sat, 24 Apr 2021 17:36:01 UTC
Severity: normal
Tags: buster
Fixed in version release.debian.org/10.10
Done: "Adam D. Barratt" <adam@adam-barratt.org.uk>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded
to debian-bugs-dist@lists.debian.org, team@security.debian.org, apo@debian.org, Debian Release Team <debian-release@lists.debian.org>:
Bug#987494; Package release.debian.org.
(Sat, 24 Apr 2021 17:36:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Utkarsh Gupta <utkarsh@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, apo@debian.org, Debian Release Team <debian-release@lists.debian.org>.
(Sat, 24 Apr 2021 17:36:03 GMT) (full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
Package: release.debian.org
User: release.debian.org@packages.debian.org
X-Debbugs-Cc: team@security.debian.org, apo@debian.org
Usertags: pu bsp-2021-04-AT-Salzburg
Tags: buster
Severity: normal
Hello,
src:fluidsynth has been affected by CVE-2021-28421 which is fixed in
sid and unblocked for bullseye. Since this affects buster as well, I'm
hereby opening a pu update bug for tracking.
Thanks to Reiner Herrmann for preparing and testing the update. I've
reviewed and it looks good; the debdiff is duly attached. Let me know
if you need any more information. TIA!
- u
[fluidsynth-buster.debdiff (application/octet-stream, attachment)]
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Release Team <debian-release@lists.debian.org>:
Bug#987494; Package release.debian.org.
(Mon, 03 May 2021 18:09:04 GMT) (full text, mbox, link).
Acknowledgement sent
to Adam D Barratt <adam@adam-barratt.org.uk>:
Extra info received and forwarded to list. Copy sent to Debian Release Team <debian-release@lists.debian.org>.
(Mon, 03 May 2021 18:09:04 GMT) (full text, mbox, link).
Message #10 received at 987494@bugs.debian.org (full text, mbox, reply):
package release.debian.org
tags 987494 = buster pending
thanks
Hi,
The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian buster.
Thanks for your contribution!
Upload details
==============
Package: fluidsynth
Version: 1.1.11-1+deb10u1
Explanation: fix use-after-free issue [CVE-2021-28421]
Added tag(s) pending.
Request was from Adam D Barratt <adam@adam-barratt.org.uk>
to control@bugs.debian.org.
(Mon, 03 May 2021 18:09:10 GMT) (full text, mbox, link).
Message sent on
to Utkarsh Gupta <utkarsh@debian.org>:
Bug#987494.
(Mon, 03 May 2021 18:09:17 GMT) (full text, mbox, link).
Reply sent
to "Adam D. Barratt" <adam@adam-barratt.org.uk>:
You have taken responsibility.
(Sat, 19 Jun 2021 10:00:38 GMT) (full text, mbox, link).
Notification sent
to Utkarsh Gupta <utkarsh@debian.org>:
Bug acknowledged by developer.
(Sat, 19 Jun 2021 10:00:38 GMT) (full text, mbox, link).
Message #20 received at 987494-done@bugs.debian.org (full text, mbox, reply):
Package: release.debian.org
Version: 10.10
Hi,
Each of the updates referenced in these bugs was included in the 10.10
point release today.
Regards,
Adam
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Sun, 18 Jul 2021 07:30:25 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Sun Oct 8 03:09:23 2023;
Machine Name:
bembo
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.