Bug#873718: Fixes for security vulnerabilities on libgig?

2017-10-13 Thread Jaromír Mikeš
2017-10-03 20:07 GMT+02:00 Christian Schoenebeck < schoeneb...@linuxsampler.org>: Hi Christian, > I just applied your patch regarding CVE-2017-12950, CVE-2017-12952 and > CVE-2017-12953 for libgig on our side, in slightly modified form: > >

Bug#873718: Fixes for security vulnerabilities on libgig?

2017-10-03 Thread Christian Schoenebeck
Hi there, I just applied your patch regarding CVE-2017-12950, CVE-2017-12952 and CVE-2017-12953 for libgig on our side, in slightly modified form: http://svn.linuxsampler.org/cgi-bin/viewvc.cgi?view=revision=3348 Additionally, the following 2 patches are yet missing on your side, as far as I

Bug#873718: Fixes for security vulnerabilities on libgig?

2017-08-30 Thread Christian Schoenebeck
On Wednesday, August 30, 2017 15:09:39 Raphael Hertzog wrote: > [ Copy to the Debian bugtracker ] > > Hello Christian, Hi Raphael, > a few security issues have been reported against libgig: > http://seclists.org/fulldisclosure/2017/Aug/39 > > The reproducer files are attached too: >

Bug#873718: Fixes for security vulnerabilities on libgig?

2017-08-30 Thread Salvatore Bonaccorso
On Wed, Aug 30, 2017 at 04:34:44PM +0200, Salvatore Bonaccorso wrote: > Hi > > All, but not CVE-2017-12951 are probably fixed already with the > 4.0.0-4 upload to unstable today. Might actually just uncover another problem after the fix. Regards, Salvatore

Bug#873718: Fixes for security vulnerabilities on libgig?

2017-08-30 Thread Salvatore Bonaccorso
Hi All, but not CVE-2017-12951 are probably fixed already with the 4.0.0-4 upload to unstable today. Regards, Salvatore

Bug#873718: Fixes for security vulnerabilities on libgig?

2017-08-30 Thread Raphael Hertzog
[ Copy to the Debian bugtracker ] Hello Christian, a few security issues have been reported against libgig: http://seclists.org/fulldisclosure/2017/Aug/39 The reproducer files are attached too: http://seclists.org/fulldisclosure/2017/Aug/att-39/poc_zip.bin I wanted to check that you were aware