Bug#908698: smarty3: CVE-2018-16831

2019-12-10 Thread Mike Gabriel
Hi Salvatore, On Sa 07 Dez 2019 16:30:16 CET, Salvatore Bonaccorso wrote: Hi Mike, On Fri, Feb 15, 2019 at 10:50:32PM +, Mike Gabriel wrote: Hi Moritz, Salvatore, On Do 27 Dez 2018 21:44:33 CET, Salvatore Bonaccorso wrote: > Hi Mike, > > On Thu, Nov 22, 2018 at 08:00:07PM +0100,

Bug#908698: smarty3: CVE-2018-16831

2019-02-15 Thread Mike Gabriel
Hi Moritz, Salvatore, On Do 27 Dez 2018 21:44:33 CET, Salvatore Bonaccorso wrote: Hi Mike, On Thu, Nov 22, 2018 at 08:00:07PM +0100, Moritz Mühlenhoff wrote: On Fri, Oct 26, 2018 at 04:46:39PM +, mike.gabr...@das-netzwerkteam.de wrote: > Hi, > > On Friday, 26 October 2018, Moritz

Bug#908698: smarty3: CVE-2018-16831

2019-01-28 Thread Moritz Mühlenhoff
On Thu, Dec 27, 2018 at 09:44:33PM +0100, Salvatore Bonaccorso wrote: > Hi Mike, > > On Thu, Nov 22, 2018 at 08:00:07PM +0100, Moritz Mühlenhoff wrote: > > On Fri, Oct 26, 2018 at 04:46:39PM +, mike.gabr...@das-netzwerkteam.de > > wrote: > > > Hi, > > > > > > On Friday, 26 October 2018,

Bug#908698: smarty3: CVE-2018-16831

2018-09-18 Thread Moritz Mühlenhoff
On Tue, Sep 18, 2018 at 05:06:14PM +, Mike Gabriel wrote: > > But let's wait for a few more days to spot eventual regressions reported > > in unstable first. Also, make sure to coordinate the release of the DLA with > > the DSA, otherwise we end up with a situation where oldstable has a higher

Bug#908698: smarty3: CVE-2018-16831

2018-09-18 Thread Mike Gabriel
Hi, On Mo 17 Sep 2018 23:20:33 CEST, Moritz Mühlenhoff wrote: On Mon, Sep 17, 2018 at 09:07:38PM +, Mike Gabriel wrote: I have looked at the changes between 3.1.33 (just uploaded to unstable) and 3.1.31 (in stable). They are awful. Read the below... 15:42 < sunweaver> Hi all, I have

Bug#908698: smarty3: CVE-2018-16831

2018-09-17 Thread Moritz Mühlenhoff
On Mon, Sep 17, 2018 at 09:07:38PM +, Mike Gabriel wrote: > I have looked at the changes between 3.1.33 (just uploaded to unstable) and > 3.1.31 (in stable). They are awful. Read the below... > > 15:42 < sunweaver> Hi all, I have just looked into >

Bug#908698: smarty3: CVE-2018-16831

2018-09-17 Thread Mike Gabriel
(Re-sending, with security@d.o in Cc: now). Hi Salvatore, On Mi 12 Sep 2018 21:37:18 CEST, Salvatore Bonaccorso wrote: Source: smarty3 Version: 3.1.32+20180424.1.ac9d4b58+selfpack1-1 Severity: important Tags: security upstream Forwarded: https://github.com/smarty-php/smarty/issues/486 Hi,

Bug#908698: smarty3: CVE-2018-16831

2018-09-17 Thread Mike Gabriel
Hi again, On Mi 12 Sep 2018 21:37:18 CEST, Salvatore Bonaccorso wrote: Source: smarty3 Version: 3.1.32+20180424.1.ac9d4b58+selfpack1-1 Severity: important Tags: security upstream Forwarded: https://github.com/smarty-php/smarty/issues/486 ... I just noticed, 3.1.31 is in stable... But alas,

Bug#908698: smarty3: CVE-2018-16831

2018-09-17 Thread Mike Gabriel
Hi Salvatore, On Mi 12 Sep 2018 21:37:18 CEST, Salvatore Bonaccorso wrote: Source: smarty3 Version: 3.1.32+20180424.1.ac9d4b58+selfpack1-1 Severity: important Tags: security upstream Forwarded: https://github.com/smarty-php/smarty/issues/486 Hi, The following vulnerability was published for

Bug#908698: smarty3: CVE-2018-16831

2018-09-12 Thread Salvatore Bonaccorso
Source: smarty3 Version: 3.1.32+20180424.1.ac9d4b58+selfpack1-1 Severity: important Tags: security upstream Forwarded: https://github.com/smarty-php/smarty/issues/486 Hi, The following vulnerability was published for smarty3. CVE-2018-16831[0]: | Smarty before 3.1.33-dev-4 allows attackers to