Debian updates not being merged in a timely manner

Status
Not open for further replies.

Dave Braford-Grimes

Customer
Joined
Jul 21, 2017
Messages
7
Reaction score
1
I’ve noticed many package releases are not merged into your private downstream repo in a timely manner.
Is there an alternate solution to keep 3CX as secure as possible?

Some are noted with severe or critical security flaws - here are current examples:

OpenSSL -
https://security-tracker.debian.org/tracker/CVE-2022-1292

LibXML -
https://security-tracker.debian.org/tracker/source-package/libxml2

DPKG -
https://security-tracker.debian.org/tracker/CVE-2022-1664

Kernel -

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=988044
https://security-tracker.debian.org/tracker/source-package/linux
https://www.debian.org/security/2022/dsa-5096
https://security-tracker.debian.org/tracker/CVE-2020-29374
https://security-tracker.debian.org/tracker/CVE-2020-36322
https://security-tracker.debian.org/tracker/CVE-2021-20317
https://security-tracker.debian.org/tracker/CVE-2021-20321
https://security-tracker.debian.org/tracker/CVE-2021-20322
https://security-tracker.debian.org/tracker/CVE-2021-22600
https://security-tracker.debian.org/tracker/CVE-2021-28711
https://security-tracker.debian.org/tracker/CVE-2021-28712
https://security-tracker.debian.org/tracker/CVE-2021-28713
https://security-tracker.debian.org/tracker/CVE-2021-28714
https://security-tracker.debian.org/tracker/CVE-2021-28715
https://security-tracker.debian.org/tracker/CVE-2021-28950
https://security-tracker.debian.org/tracker/CVE-2021-3640
https://security-tracker.debian.org/tracker/CVE-2021-3744
https://security-tracker.debian.org/tracker/CVE-2021-3752
https://security-tracker.debian.org/tracker/CVE-2021-3760
https://security-tracker.debian.org/tracker/CVE-2021-3764
https://security-tracker.debian.org/tracker/CVE-2021-3772
https://security-tracker.debian.org/tracker/CVE-2021-38300
https://security-tracker.debian.org/tracker/CVE-2021-39685
https://security-tracker.debian.org/tracker/CVE-2021-39686
https://security-tracker.debian.org/tracker/CVE-2021-39698
https://security-tracker.debian.org/tracker/CVE-2021-39713
https://security-tracker.debian.org/tracker/CVE-2021-4002
https://security-tracker.debian.org/tracker/CVE-2021-4083
https://security-tracker.debian.org/tracker/CVE-2021-4135
https://security-tracker.debian.org/tracker/CVE-2021-4155
https://security-tracker.debian.org/tracker/CVE-2021-41864
https://security-tracker.debian.org/tracker/CVE-2021-4202
https://security-tracker.debian.org/tracker/CVE-2021-4203
https://security-tracker.debian.org/tracker/CVE-2021-42739
https://security-tracker.debian.org/tracker/CVE-2021-43389
https://security-tracker.debian.org/tracker/CVE-2021-43975
https://security-tracker.debian.org/tracker/CVE-2021-43976
https://security-tracker.debian.org/tracker/CVE-2021-44733
https://security-tracker.debian.org/tracker/CVE-2021-45095
https://security-tracker.debian.org/tracker/CVE-2021-45469
https://security-tracker.debian.org/tracker/CVE-2021-45480
https://security-tracker.debian.org/tracker/CVE-2022-0001
https://security-tracker.debian.org/tracker/CVE-2022-0002
https://security-tracker.debian.org/tracker/CVE-2022-0322
https://security-tracker.debian.org/tracker/CVE-2022-0330
https://security-tracker.debian.org/tracker/CVE-2022-0435
https://security-tracker.debian.org/tracker/CVE-2022-0487
https://security-tracker.debian.org/tracker/CVE-2022-0492
https://security-tracker.debian.org/tracker/CVE-2022-0617
https://security-tracker.debian.org/tracker/CVE-2022-0644
https://security-tracker.debian.org/tracker/CVE-2022-22942
https://security-tracker.debian.org/tracker/CVE-2022-24448
https://security-tracker.debian.org/tracker/CVE-2022-24959
https://security-tracker.debian.org/tracker/CVE-2022-25258
https://security-tracker.debian.org/tracker/CVE-2022-25375
 
  • Like
Reactions: Bruce Brewer
Are you saying you have auto-updates on and those packages aren't being updated?
 
I don't have auto updates on - that's crazy ;)
We monitor our PBX with 3rd party software that identifies packages that are reported with vulnerabilities.
For that past year, there has been significant delays in those packages being available via the default 3CX repo.
Here are the entries in /etc/apt/sources.list:

deb [arch=amd64 by-hash=yes signed-by=/usr/share/keyrings/3cx-archive-keyring.gpg] http://repo.3cx.com/debian/1803 buster main
deb [arch=amd64 by-hash=yes signed-by=/usr/share/keyrings/3cx-archive-keyring.gpg] http://repo.3cx.com/debian-security/1803 buster main

I would just add the Debian defaults to /etc/apt/sources.list (and the upcoming LTS entries).
But, it seems risky.
 
Thank you Saqqara - but, I assume you see how this doesn't help of solve the issue at hand.
The "testing updates" are taking A LONG TIME and during that time, every single 3CX instance could possibly be exploited.

Some of the package exploits aren't too bad, but some are.
I also understand that some Debian release make break 3CX or dependent features.

There needs to be faster response, that's all I'm saying.
 
How would you know how long 3CX takes to patch updates when you have auto updates turned off?
 
We monitor our PBX with 3rd party software that identifies packages that are reported with vulnerabilities.
For that past year, there has been significant delays in those packages being available via the default 3CX repo.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,900
Latest member
Silent_Guru