Bug#850160: Incomplete fix (was: Re: Bug#850160 closed by Reiner Herrmann <rei...@reiner-h.de> (Bug#850160: fixed in firejail 0.9.44.2-2))

2017-01-06 Thread Salvatore Bonaccorso
Hi Reiner, On Fri, Jan 06, 2017 at 12:37:23PM +0100, Reiner Herrmann wrote: > Hi Moritz, > > On Fri, Jan 06, 2017 at 10:53:17AM +0100, Moritz Muehlenhoff wrote: > > there have been new CVE assignments for firejail. Most of them are fixed in > > stretch, but two of those have not made it into a

Bug#850160: Incomplete fix (was: Re: Bug#850160 closed by Reiner Herrmann <rei...@reiner-h.de> (Bug#850160: fixed in firejail 0.9.44.2-2))

2017-01-06 Thread Reiner Herrmann
Hi Moritz, On Fri, Jan 06, 2017 at 10:53:17AM +0100, Moritz Muehlenhoff wrote: > there have been new CVE assignments for firejail. Most of them are fixed in > stretch, but two of those have not made it into a firejail release: They are part of the bugfix release 0.9.44.2:

Bug#850160: Incomplete fix (was: Re: Bug#850160 closed by Reiner Herrmann <rei...@reiner-h.de> (Bug#850160: fixed in firejail 0.9.44.2-2))

2017-01-06 Thread Moritz Muehlenhoff
On Thu, Jan 05, 2017 at 11:17:01AM +0100, Reiner Herrmann wrote: > Control: reopen -1 > > Hi Salvatore, > > On Thu, Jan 05, 2017 at 07:54:24AM +0100, Salvatore Bonaccorso wrote: > > On Wed, Jan 04, 2017 at 11:21:05PM +, Debian Bug Tracking System wrote: > > >* Add upstream fix for

Bug#850160: Incomplete fix (was: Re: Bug#850160 closed by Reiner Herrmann <rei...@reiner-h.de> (Bug#850160: fixed in firejail 0.9.44.2-2))

2017-01-05 Thread Reiner Herrmann
Control: reopen -1 Hi Salvatore, On Thu, Jan 05, 2017 at 07:54:24AM +0100, Salvatore Bonaccorso wrote: > On Wed, Jan 04, 2017 at 11:21:05PM +, Debian Bug Tracking System wrote: > >* Add upstream fix for CVE-2017-5180 (Closes: #850160). > > Thanks. The fix had a followup which does not

Bug#850160: Incomplete fix (was: Re: Bug#850160 closed by Reiner Herrmann <rei...@reiner-h.de> (Bug#850160: fixed in firejail 0.9.44.2-2))

2017-01-04 Thread Salvatore Bonaccorso
Hi Reiner, On Wed, Jan 04, 2017 at 11:21:05PM +, Debian Bug Tracking System wrote: >* Add upstream fix for CVE-2017-5180 (Closes: #850160). Thanks. The fix had a followup which does not seem to be applied, cf. https://github.com/netblue30/firejail/issues/1020#issuecomment-270514760