Bug#840227: libgit2: CVE-2016-8568 CVE-2016-8569

2017-01-02 Thread Salvatore Bonaccorso
Hi Russell, On Tue, Jan 03, 2017 at 05:55:31PM +1100, Russell Sim wrote: > Hi, > > Sorry, I messed this up. > > The fix for CVE-2016-8569 was included in the 0.24.2-1 release but the > fix for CVE-2016-8568 wasn't. > > Sorry about that, I have pushed a new version to unstable that includes >

Bug#840227: libgit2: CVE-2016-8568 CVE-2016-8569

2017-01-02 Thread Russell Sim
Hi, Sorry, I messed this up. The fix for CVE-2016-8569 was included in the 0.24.2-1 release but the fix for CVE-2016-8568 wasn't. Sorry about that, I have pushed a new version to unstable that includes the fix, the version is 0.24.5-1. I realised the mistake when I was reviewing some diffs

Bug#840227: libgit2: CVE-2016-8568 CVE-2016-8569

2016-10-09 Thread Salvatore Bonaccorso
Source: libgit2 Version: 0.24.1-2 Severity: grave Tags: security upstream Hi, the following vulnerabilities were published for libgit2. CVE-2016-8568[0, 3]: Read out-of-bounds in git_oid_nfmt CVE-2016-8569[1, 4]: DoS using a null pointer dereference in git_commit_message If you fix the