Bug 57256 - emacs24: Multiple issues (4.4)
emacs24: Multiple issues (4.4)
Status: ASSIGNED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.4
All Linux
: P5 normal (vote)
: UCS 4.4-9-errata
Assigned To: Quality Assurance
Iván.Delgado
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2024-05-06 08:05 CEST by Quality Assurance
Modified: 2024-05-15 11:58 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 0.0 () debian/changelog


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2024-05-06 08:05:32 CEST
New Debian emacs24 24.5+1-11+deb9u3 fixes:
This update addresses the following issues:

Debian update 24.5+1-11+deb9u3
24.5+1-11+deb9u3 (Fri, 03 May 2024 12:49:30 +0100)
* Non-maintainer upload by the ELTS Team.
* Fix CVE-2024-30203, CVE-2024-30204 & CVE-2024-30205.
Comment 1 Philipp Hahn univentionstaff 2024-05-14 16:14:28 CEST
https://www.freexian.com/lts/extended/updates/ela-1085-1-emacs24/
https://deb.freexian.com/extended-lts/pool/main/e/emacs24/
file://omar/mnt/build-storage/upstream/freexian/pool/main/e/emacs24/*_24.5+1-11+deb9u3*
file://omar/var/univention/buildsystem2/apt/ucs_4.4-0-errata4.4-9/source/emacs24*_24.5+1-11+deb9u3*
Comment 2 Philipp Hahn univentionstaff 2024-05-15 11:58:47 CEST
FYI:
1. The Freexian upload is incomplete: the *binary* packages for amd64 and i386 are missing
2. Therefor our "local mirror on file:///omar/mnt/build-storage/upstream/freexian/ is also missing them
3. `repo-debmirror` therefore imported *only* the *source* package files, e.g. `.dsc`, `.orig.tar.*z*`, `.debian.tar.*z*`
4. `repo-ng-auto-build` found the new `.dsc` file but no corresponding `_amd64.deb` files and thus decided to build the binary packages itself.

RFA:
1. Inform Freexian about the missing packages
2. Remove our build from `apt/`
3. Remove any artifacts from `piuparts`
4. ~~Reset Bugzilla to ASSIGNED~~
5. Re-import from Freexian
6. Make sure to run `repo-apt-ftparchive --stat` to force a cache update
7. Continue with the erratum release as normal