Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-14 Thread Mike Hommey
On Sat, Dec 12, 2009 at 10:56:59PM -0500, Michael Gilbert wrote: package: xulrunner severity: serious tags: security Hi, The following CVE (Common Vulnerabilities Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and

Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-14 Thread Michael Gilbert
retitle 560946 xulrunner: embeds expat severity 560946 important thanks On Mon, 14 Dec 2009 09:15:12 +0100, Mike Hommey wrote: On Sat, Dec 12, 2009 at 10:56:59PM -0500, Michael Gilbert wrote: package: xulrunner severity: serious tags: security Hi, The following CVE (Common

Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-14 Thread Michael Gilbert
On Mon, 14 Dec 2009 17:48:10 +0100, Mike Hommey wrote: tag 560946 wontfix thanks On Mon, Dec 14, 2009 at 11:31:18AM -0500, Michael Gilbert wrote: retitle 560946 xulrunner: embeds expat severity 560946 important thanks On Mon, 14 Dec 2009 09:15:12 +0100, Mike Hommey wrote: On

Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-14 Thread Mike Hommey
tag 560946 wontfix thanks On Mon, Dec 14, 2009 at 11:31:18AM -0500, Michael Gilbert wrote: retitle 560946 xulrunner: embeds expat severity 560946 important thanks On Mon, 14 Dec 2009 09:15:12 +0100, Mike Hommey wrote: On Sat, Dec 12, 2009 at 10:56:59PM -0500, Michael Gilbert wrote:

Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: xulrunner severity: serious tags: security Hi, The following CVE (Common Vulnerabilities Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many