Prepare stable update of unbound
Hi @dleidert ,
We received a report from the security team concerning a package which has one or more CVEs fixed by a DLA, but the same CVEs remain unfixed in more recent releases. In this case, the remaining open CVEs have been marked by the security team, so they have no immediate plans to deal with them. Please coordinate with the maintainer and SRM to have an updated package included in the next point release (for CVEs affecting bookworm) and/or prepare a supplementary DLA (for CVEs affecting bullseye). Additionally, please keep the security team informed concerning this matter by mailing team@security.debian.org with a brief summary once a course of action has been agreed upon between yourself, the maintainer, and SRM (as applicable).
- Package: unbound
- DLA: DLA-3952-1, https://lists.debian.org/debian-lts-announce/2024/11/msg00009.html
- Version in DLA: 1.13.1-1+deb11u4
- CVE(s): CVE-2024-8508
- Fixed in: bullseye
- Still present in: bookworm