Re: Gpsd v3.20 failing 23 October 2021

From: TarotApprentice
Subject: Re: Gpsd v3.20 failing 23 October 2021
Date: Thu, 29 Jul 2021 21:47:33 +0000 (UTC)

Corrected the subject line. Don’t you love spell checkers that think they know better than the person typing.

From an earlier email on this list replying to someone else you wrote:

>> pi@raspberrypi:~ $ gpsd -V
>> gpsd: 3.20 (revision 3.20)
>Almost 2 years old.  known CVE, and will fail on 23 October 2021.

Can you give some more info please, like the CVE number, where to get the patch and what symptoms will it have when it fails.

I will file a bug with Debian so they can look into it. Also what version has it fixed, in case the choose to upgrade to a later version? Debian have announced they are expecting to release Debian 11 on the 14th of August so it will be too late to get it in there but they might be able to use a backports repo.


