Bug#802231: jq: CVE-2015-8863: Heap buffer overflow in tokenadd()

2016-10-03 Thread Nicholas Luedtke
Maintainer, Upstream hasn't had a release in over a year, any thoughts to applying a patch for this CVE? Thanks. -- Nicholas Luedtke HPE Linux, Hewlett-Packard Enterprise signature.asc Description: OpenPGP digital signature

Bug#802231: jq: CVE-2015-8863: Heap buffer overflow in tokenadd()

2016-10-03 Thread Nicholas Luedtke
Maintainer, Upstream hasn't had a release in over a year, any thoughts to applying a patch for this CVE? Thanks. -- Nicholas Luedtke HPE Linux Security, Hewlett-Packard Enterprise signature.asc Description: OpenPGP digital signature

Bug#802231: jq: CVE-2015-8863

2016-08-01 Thread Harlan Lieberman-Berg
Hello Simon, Is there any possibility of shipping the patch for CVE-2015-8863 out of a release cycle? Upstream seems to be going through a period of idleness, but I'd really like to see the fix in. Thanks! -- Harlan Lieberman-Berg ~hlieberman