Bug#560948: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-19 Thread Norbert Preining
Hi Hilmar, On Mo, 14 Dez 2009, Hilmar Preuße wrote: notfound 2007.dfsg.2-4+lenny1 notfound 2009-3 stop Thanks for that, do you understand why it still shows up as RC bug for texlive-bin??? I tend to close this bug simply with an email to NNN-done ... Best wishes Norbert

Bug#560948: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-19 Thread Hilmar Preuße
On 19.12.09 Norbert Preining (prein...@logic.at) wrote: On Mo, 14 Dez 2009, Hilmar Preuße wrote: Hi, notfound 2007.dfsg.2-4+lenny1 notfound 2009-3 stop Thanks for that, do you understand why it still shows up as RC bug for texlive-bin??? I didn't really understand yet that

Bug#560948: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-14 Thread Hilmar Preuße
notfound 2007.dfsg.2-4+lenny1 notfound 2009-3 stop On 13.12.09 Michael Gilbert (michael.s.gilb...@gmail.com) wrote: package: texlive-bin severity: serious tags: security Hi, The following CVE (Common Vulnerabilities Exposures) ids were published for expat. I have determined that this

Bug#560948: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: texlive-bin severity: serious tags: security Hi, The following CVE (Common Vulnerabilities Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many