Opened 2 years ago

Closed 2 years ago

Last modified 2 years ago

#19964 closed enhancement (fixed)

cryptsetup-2.7.3

Reported by: Bruce Dubbs Owned by: Rahul Chandra
Priority: elevated Milestone: 12.2
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (8)

comment:2 by Rahul Chandra, 2 years ago

Owner: changed from blfs-book to Rahul Chandra
Status: new → assigned

comment:3 by Rahul Chandra, 2 years ago

Priority: normal → elevated

comment:4 by Rahul Chandra, 2 years ago

For some reason they don't have a CVE for the security fixes

comment:5 by Rahul Chandra, 2 years ago

SA 12.1-065 issued

comment:7 by Rahul Chandra, 2 years ago

Resolution: → fixed
Status: assigned → closed

in reply to:  4 comment:8 by Douglas R. Reno, 2 years ago

Replying to Rahul Chandra:

For some reason they don't have a CVE for the security fixes

I think that's kind of weird as well. I've done a little bit of research into it and haven't come up with anything, and no other distros seem to have done a security response for this update.

Filing an SA was definitely the right call though because of the data destruction bug. I think the best course of action might be to modify the security advisory to point towards the release notes just so that users can find additional info there if they need it.

Note: See TracTickets for help on using tickets.