Received: from mx0b-00069f02.pphosted.com (mx0b-00069f02.pphosted.com [205.220.177.32]) by gbr-app-1.alpinelinux.org (Postfix) with ESMTPS id 6CABB222F3F for <~alpine/users@lists.alpinelinux.org>; Tue, 6 Aug 2024 04:07:46 +0000 (UTC) Received: from pps.filterd (m0333520.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.18.1.2/8.18.1.2) with ESMTP id 47621PBV002045 for <~alpine/users@lists.alpinelinux.org>; Tue, 6 Aug 2024 04:07:44 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h= from:to:subject:date:message-id:content-type:mime-version; s= corp-2023-11-20; bh=Ge4oqjhVjX5+SETJpqkSaCEmNPhDIN93aZ3VypXxpe0=; b= P2qiIJQyMEhobGQ3BFAOYg6j0C16rGWBM3kKqR6pj17ijWbwihCTaH0j/0vpSg0n emQAKhGcL0SBPeZOxGwb9TA1PPqUGyaYJQzM799BQrm0nAEdhXWSjIRuGG4b4XWe Z+l6WE5PBI/sDwHa4lgWSHzclhPnJxrtkYTlgRdkfXXrR+yg+0RTkTLQCv+DQfRu 2OwmJiMkXUu0mNtMrZ3YEhbtJFYOaXibuVdud0eM6X97ky4ANpsX8hlduhVBPV9M eOtc9uAGYML+JIeqATWa/BKSb53pYaNhLVPuIsmy4hPxljYKre6vwcxCcWsF+f9/ PpaCrWMeQkwWHhOVJBY2aQ== Received: from iadpaimrmta02.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta02.appoci.oracle.com [147.154.18.20]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 40sckccdkt-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK) for <~alpine/users@lists.alpinelinux.org>; Tue, 06 Aug 2024 04:07:44 +0000 (GMT) Received: from pps.filterd (iadpaimrmta02.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by iadpaimrmta02.imrmtpd1.prodappiadaev1.oraclevcn.com (8.17.1.19/8.17.1.19) with ESMTP id 4763Mdpm016986 for <~alpine/users@lists.alpinelinux.org>; Tue, 6 Aug 2024 04:07:43 GMT Received: from nam04-mw2-obe.outbound.protection.outlook.com (mail-mw2nam04lp2175.outbound.protection.outlook.com [104.47.73.175]) by iadpaimrmta02.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTPS id 40sb09dp03-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK) for <~alpine/users@lists.alpinelinux.org>; Tue, 06 Aug 2024 04:07:43 +0000 ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=J53ZvRQ4eJKPRCEfGFbAbmXO2JZmp+9Jx050YZYjYUMZG1IcfFf9NKX9rDeOLrIuer332KE822RJaOEcWKS/h+NsymG/lv5Zm5lTAZeC7BwFWuAyJAky2Kkz/k4O6wK+Q2+N51zTUZ7T1wdGEz4M+sUpQldeLYHJcR32kGXF0YkQdRi0h6oDmvocxACcrumXmXOLu5DjHuljFqWaMSR6UOROGVmam13tqU9Vg+LsberhqBHJdWOnK3syKePgIvomGDCzFVex47xita+AZqbIlnFUCgfcEJQxpz71dWL3uvfRg18LkdPnhHOImgOHp/gbUl6GikbWzjAdBfuYmDd84A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Ge4oqjhVjX5+SETJpqkSaCEmNPhDIN93aZ3VypXxpe0=; b=zJYoKJkcyRSWQy+r81h9OvQmlDlQta0BKNHEM0jLEYdXAo7IdHN3QKYXDXc+RWXVJUSdkz/TMwzbARsFngFV8TBgy6kl0BWrHptXPFLei45uP1UexnuOvzQXZZ7D9EIbFKt+Yz9+K7zKp7OWyNqy3dYpDduvk+qZEK9IlEe1+t46fJuJAaxjTU+1GYy6KldIABzFM6tvI3uE6HLk7423IP6ylMacqA3zNAJBLiwfFaKRhGhOvNhPZcxu6/PTENT1cOj35kNlYZXnmlC8XhrGTIziaVLK0F3aS5RvOAMyUsWeKZ3wxRJwrfLtDLhyUyA/HeTJ/f7d56Y7c7x8uE9j/Q== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=oracle.com; dmarc=pass action=none header.from=oracle.com; dkim=pass header.d=oracle.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.onmicrosoft.com; s=selector2-oracle-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Ge4oqjhVjX5+SETJpqkSaCEmNPhDIN93aZ3VypXxpe0=; b=Obwb9JrHI+9DAgHXNmRMffHWD5/+z/MPoylTRCypIw6mJRKhRtZBob5WptV0+atqdk7DCifUpr9525hLF++2/1eP1pfhBSM3SqLiglGjNjt247yP8PC88uKK1NHSGzMulChryy0I/iO9aXEWRV/xh7dScI0Tu/N1kHbKtAuSQMI= Received: from DS0PR10MB6149.namprd10.prod.outlook.com (2603:10b6:8:c7::21) by PH8PR10MB6290.namprd10.prod.outlook.com (2603:10b6:510:1c1::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7784.19; Tue, 6 Aug 2024 04:07:40 +0000 Received: from DS0PR10MB6149.namprd10.prod.outlook.com ([fe80::61dd:522f:d49d:68bc]) by DS0PR10MB6149.namprd10.prod.outlook.com ([fe80::61dd:522f:d49d:68bc%6]) with mapi id 15.20.7828.023; Tue, 6 Aug 2024 04:07:40 +0000 From: Siddharth Srivastava To: "~alpine/users@lists.alpinelinux.org" <~alpine/users@lists.alpinelinux.org> Subject: Inquiry on CVE-2024-39689 Fix and Update Timeline Thread-Topic: Inquiry on CVE-2024-39689 Fix and Update Timeline Thread-Index: AQHa57XcEmcWOxlx/EKf2P2VT4DOqA== Date: Tue, 6 Aug 2024 04:07:40 +0000 Message-ID: Accept-Language: en-IN, en-US Content-Language: en-IN X-MS-Has-Attach: X-MS-TNEF-Correlator: msip_labels: x-ms-publictraffictype: Email x-ms-traffictypediagnostic: DS0PR10MB6149:EE_|PH8PR10MB6290:EE_ x-ms-office365-filtering-correlation-id: e200ae7d-680d-4512-419d-08dcb5cd507e x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|376014|366016|3613699012|38070700018; x-microsoft-antispam-message-info: =?iso-8859-1?Q?WPJf8OWf4m3lZlW56j2WCeNxR8794kMvoTN4xn+tYhP8fVcdAElX82sDAD?= =?iso-8859-1?Q?Ui4sKiOmn3j5tcW9OwznJxb16TnGiGJfhdTAYSDSs5FwW5Pd1w5NT9PTQ0?= =?iso-8859-1?Q?CNCWp4SrDOhqAHMIf27JQCdcpR2mE7aeqHiecqHuj6rG8WggfCOLs65zc5?= =?iso-8859-1?Q?t9mWa+/4ToP0uRfxg99xJT62aW6Enl0NyXXvu5MsKAiec5WblJOzCYsInV?= =?iso-8859-1?Q?mcvA7/IavDUW8M0SLv/Ex6y8k9j9zTrMwtfNjY/QwCgHHx4wy2AVEP0n0s?= =?iso-8859-1?Q?dvuqnJnuuvDovRAJV3SUexdqKjmFJdctqNIn7R6F/WByev1p7y7E4pPnZv?= =?iso-8859-1?Q?zvZPG3RK+CEA/hwUMLNg80x0ZJP8pnmwA4hVGmk7mtcK7tKxKtDNnpO2hD?= =?iso-8859-1?Q?x4NLFybnGT8oS2WaKzNaJ9h1gRLvHUd0V2QG71MDiH/vJwM3BmtSYCa6Uw?= =?iso-8859-1?Q?F7iEbLbjfviAzFA0LOHtLyrkfPg4Su1rgvmmoQtRBlPwLKslmiWPjeHqxh?= =?iso-8859-1?Q?0tHKSvqHaWaPuvW9+v426ZBeBGd115pluyC/kb3dyRcrncjMzaNkFmj855?= =?iso-8859-1?Q?n2EJmj+W2veWYhKa+5Wp4PZNw/a/MYT5FUh4wJvTyqsf5dFES/STFCbEx5?= =?iso-8859-1?Q?oTmkr1G13Y9AVP2nzg3sjS6XqZgv+VFkWrdpq/mgf1UmTtSNriAYCX8aDd?= =?iso-8859-1?Q?QrzaF6AaaLOlsAhUeiW7V44BpPevmYfhYGpVpwKcf9S+CvaQXCE02j+zaa?= =?iso-8859-1?Q?z6C4EpxTFH/ax0x56NBvEcmOA1w4Zam7RptEbE6MD4YUwvg3KRgY61ae0Y?= =?iso-8859-1?Q?h8dUXcQXxJkLZwQwU93vZaUQsCyO4XOqZuLkJUdup62D0MVjWkmWlJQPOr?= =?iso-8859-1?Q?womR6KHWFYoSlIzJ274NruwMhjMKIEsu1cqD1zrPATR9FOE/VU0EFSOjCK?= =?iso-8859-1?Q?7Kh7PXWQmS1FO706Pb4cQgCuknYnIJY9ru9jo5cJUCigfTKBJu4EANfrmu?= =?iso-8859-1?Q?/o/NeUgzG+VRMjIoozkLtZPz3CD/obY/WFPz13msssNLQuKhdVAslGK+gS?= =?iso-8859-1?Q?EQT9Cc3SWSyVLYNnbCLDkECNI08EbeRciO/Af8NDO6aODwDxG6bhSHDC7H?= =?iso-8859-1?Q?pFXhb6I35ziIpIvi0XcYOwA9fX58NCzwKpHLIbnXylZ5MClRBqyb/lxCce?= =?iso-8859-1?Q?X6mLwf71KPWUejjZ9DBFIoisfVWWoTPhCY+N1fjt6trMtZmGLSRyw0JRKZ?= =?iso-8859-1?Q?HCn7FIC7dJeEwfho70fjOxa1ImDj6K9Ij9TGDOLNL9Zdc+16P0U9fTZOgz?= =?iso-8859-1?Q?YSkn6jjImrUZKQN99C6GNSUs0O1sVaoRKFMBrVCAAF3Ps80SkavILvpCxd?= =?iso-8859-1?Q?uxujg+WExMxGyPIaqGsJdjEku6wfcL79XzkS4HRaIH09iY2NW1b0bJKV+W?= =?iso-8859-1?Q?PDsmOr3EgjCrcqP5yGHMey61haSCdKcsAOvGOGGiSBW2tavLbjodc2J+SH?= =?iso-8859-1?Q?M=3D?= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DS0PR10MB6149.namprd10.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(366016)(3613699012)(38070700018);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?iso-8859-1?Q?DIob1mkurPVdcGLCMNiy+nMu4kMsfNNcfzCRN1fnyz8ykcn+iaf5GOIDhJ?= =?iso-8859-1?Q?MAfBg90vL3GNexnCyYFDLm05lxzEWb17zJwKDBOxXQ0uKbnRtQZz+rl3bu?= =?iso-8859-1?Q?JrYMrzEoZYrio7mQXZ0VFj+ahXY1R/Ipw/7IAmNkGQYpIAgMipj8hizLcN?= =?iso-8859-1?Q?zu6+O9CvUTdOXo0eLY2PP51ri7ntb9pn6JShgZyLo/pr12d29dJdfhk6N0?= =?iso-8859-1?Q?dsG+IPOUukscHERTZW47n9a/fhDweyOFxSta6FZG1lfIAyEyfNxfF3O5GP?= =?iso-8859-1?Q?B2xSz1ahBHGwkUXTHKv924fg9y4WfEbXRA3pSEVEHVpJIkQUn5LMyBRbgb?= =?iso-8859-1?Q?+/fUSF85e0XpLMHpGiexAjr6OHYfcm0NlglISsCQcdMyy9WhKH30CHXXQp?= =?iso-8859-1?Q?BfKZnN88qzFjLlYzY2fKIKiHicJe6c4v/C9XZ1Kh0/aUdLHoMcOV0Y8dlv?= =?iso-8859-1?Q?herik8WeoexS9RttqXXEGC/AI4dovG8vIIWRPCosGVtGzPvffFOJtrrHPZ?= =?iso-8859-1?Q?QKiH8MdeuzGqfvKfMps6hfG+fzWA3czWAGkwgGBQ6NlpsYa4zrlIU49QKe?= =?iso-8859-1?Q?+QMsAtm3fIX6XJS5pKAI9kl9/Jq5HpiJ5I4o4fxmnYxSloI9/zJSaWWzZ0?= =?iso-8859-1?Q?qjLVbotIvJ9NkCY6WKQykOpqoLlCGJdoKEey0u83I52l+LKouvX7acQNTn?= =?iso-8859-1?Q?GRnAKRJ/MhaYnXi0iuf8iDn1OVd9rlutNDp85qu0VxCAt+GLDqPB5W24DD?= =?iso-8859-1?Q?ZOZ7dvuvkATafzh1VmnqSNmz/ZoOUYeX5A141O/U7oxpFCZunSp72jb7El?= =?iso-8859-1?Q?c+g5NLgJnVZZRTreumfR/U+BcgnrlwcjaZpTNavEe2Zi1UZkpwfxfig89R?= =?iso-8859-1?Q?17uwvguC+N4XSxPpD2rQj94+FVrVk30BNOQ2h/lx3eDhwJh0FDcRO8PUht?= =?iso-8859-1?Q?wURQ2WngNz1I9qGS8HYLilUkuBQTB16Zlf0467HyTdz+tlqaRDIim3+zD7?= =?iso-8859-1?Q?ULn+0Ns9dVqBwPoOBqOBg9pfVBjGhu5u917r+OeKwT4dGOR1IAEUQ4cON7?= =?iso-8859-1?Q?o5pvqS4ZvIdywKlED77j7zm/RTH5eUwBt+ITvYiiP++p9JTw5bGotCp8Qj?= =?iso-8859-1?Q?8pus9LZtpbg1DhQVEY8ggM8WB5ds2Rt0OrncrA2YTpn4FFyhF0Wuex2B3y?= =?iso-8859-1?Q?3H0618FFo6rsnzFMsnIb+FQNMZ2SUFSwxxHYTS8gjuxpR4cmAe9KCmcYjD?= =?iso-8859-1?Q?M1+ICIPnu9rdlw/VS1mvVN9hN5s2553+UJIBBfR9UZtaPgTfljaofMdnX2?= =?iso-8859-1?Q?iJ4YbpVb1I6tiAD1QSHvQ7gTdTYOvCMDuDB4M0JkZc0lL2zujvk1WjqjYR?= =?iso-8859-1?Q?vnIpRhNqGYXGWpW0yVsT2W3dczMRcCZi7YNKl7O6Fi+LYpE5LjVrS+kxB4?= =?iso-8859-1?Q?p5Ub3muEovRBAvUCPkPwIbV7zcujuTb1h5rcdrGslcP5P3QlHkFvqSAUaj?= =?iso-8859-1?Q?JWXYTeNMachS0Y5vovwbIGBljGjQ2ynCGCIuszPsmlPbVt5/27Jv7SDnl7?= =?iso-8859-1?Q?vZ1Ue75fnW603Bbc6PN9sevnCghBWPPe3gXzs9z3U2NvtevctVZWjwNZzf?= =?iso-8859-1?Q?ZdXX1R6ve/69p7ivGQgnljxo8JoUO+bqgCuna02+lkllnHuN8E1AnjOg?= =?iso-8859-1?Q?=3D=3D?= Content-Type: multipart/alternative; boundary="_000_DS0PR10MB6149F8CED4DC162A27A41793A3BF2DS0PR10MB6149namp_" MIME-Version: 1.0 X-MS-Exchange-AntiSpam-ExternalHop-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-ExternalHop-MessageData-0: R0Iey8xv2144ifskUBibN4OQw/6gmmoZd15yNG74tNPTP/FV7GNceaKSPE/AYWKyYqITmFyNgv09ttPr6W+5iZmmNjqBQKAVLsUtBUYjo38M9M7hlHHV7zV8SNyPATVSbyj6cmUGRRM6ycThqQk33fE1bK3lEenncR5dWwUW9X0FnPnyBGjXOgmkXof87Obh4VZdPdYsTnfivzHLiWbjv5cS8Ol+ao/TOwOO2Cs3aFWngqT+U/+dJLiAf6pa1hkajg+F4kAYfl5/DYsRPJNHmsYfHRGn+LHsNjX6ubeLtxX7cTQ9nvhNyYh5wf9rnEaDiaQm9j2ip3OO26Z112a+YpBPsxD7pd7rnz2s2yE4OAxceC5OaQuXGSAHFESqC4tFvS7o9fbfKSFowNey+tQiP8p8TVh2dZyciXHg5ID89J4WmPK3L/HOBXeTpqC/KHEjpFhTCdkN75RwLmEWaAiWYySd/lkn5+z4CLe6CmbJ4oww2DL3E1qotdzzcYQSfMVSgnI/iaIDU4C5H3eX5jJoh2a+qrcmYXZS3G5by7nY87HrYZElyI7ONyZKzwCkJNED+GSvG5BwgwdaA2JawWsDwkqKUbi1VBMLmUrHhB014+E= X-OriginatorOrg: oracle.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: DS0PR10MB6149.namprd10.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: e200ae7d-680d-4512-419d-08dcb5cd507e X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Aug 2024 04:07:40.2604 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 4e2c6054-71cb-48f1-bd6c-3a9705aca71b X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: v4wkVdJoVLIqvl1ZJYhaDkNTc7nWym6Igfp0S68HZIUxGgLzV02p1MtwIwqArB8qcWcF6ks8bGPqKfR5CewMD0VgehTLzZ2KHlte5BpKXmA6hvgaSRqv1PKOmYWa8F6T X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH8PR10MB6290 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1039,Hydra:6.0.680,FMLib:17.12.28.16 definitions=2024-08-06_02,2024-08-02_01,2024-05-17_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 phishscore=0 suspectscore=0 adultscore=0 bulkscore=0 malwarescore=0 mlxlogscore=999 mlxscore=0 spamscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2407110000 definitions=main-2408060027 X-Proofpoint-GUID: DPa0SacHdUuMMsPfMwVehNUAHFXG-wPm X-Proofpoint-ORIG-GUID: DPa0SacHdUuMMsPfMwVehNUAHFXG-wPm --_000_DS0PR10MB6149F8CED4DC162A27A41793A3BF2DS0PR10MB6149namp_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Dear Alpine Team, I am writing to inquire about the fix for CVE-2024-39689 in Alpine Linux. O= ur team has noted that the current latest available version of alpine 3.20 = is using py3-certifi 2024.2.2 version and is still affected by this vulnera= bility. Given the importance of maintaining security and stability in our s= ystems, we are keen to update to a version that addresses this issue. Could you kindly provide us with information on when the fix will be releas= ed and an estimated timeline for the availability of the updated version 20= 24.07.04? Your prompt response would be greatly appreciated as it will help us in pla= nning our update process accordingly. Thank you for your attention to this matter. Best regards, Siddharth Srivastava --_000_DS0PR10MB6149F8CED4DC162A27A41793A3BF2DS0PR10MB6149namp_ Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Dear Alpine Team,
I am writing to inquire about the fix for CVE-2024-39689 in Alpine Linux. O= ur team has noted that the current latest available version of alpine 3.20 = is using py3-certifi 2024.2.2 version and is still affected by this vulnera= bility. Given the importance of maintaining security and stability in our systems, we are keen to update t= o a version that addresses this issue.
Could you kindly provide us with information on when the fix will be releas= ed and an estimated timeline for the availability of the updated version 20= 24.07.04?
Your prompt response would be greatly appreciated as it will help us in pla= nning our update process accordingly.
Thank you for your attention to this matter.
Best regards,
Siddharth Srivastava
--_000_DS0PR10MB6149F8CED4DC162A27A41793A3BF2DS0PR10MB6149namp_--