Bug#910448: mgetty: CVE-2018-16741

2018-10-06 Thread Andreas Barth
* Salvatore Bonaccorso (car...@debian.org) [181006 21:21]: > FTR, I think if feasible best would be to go for unstable (and thus > buster) directly to 1.2.1, which will adress as well the other CVEs > (which were no-dsa or unimportant). That's the plan, yes. Andi

Bug#910448: mgetty: CVE-2018-16741

2018-10-06 Thread Salvatore Bonaccorso
Hi, FTR, I think if feasible best would be to go for unstable (and thus buster) directly to 1.2.1, which will adress as well the other CVEs (which were no-dsa or unimportant). Regards, Salvatore

Bug#910448: mgetty: CVE-2018-16741

2018-10-06 Thread Salvatore Bonaccorso
Source: mgetty Version: 1.1.36-1 Severity: grave Tags: patch security upstream Control: fixed -1 1.1.36-3+deb9u1 Hi, The following vulnerability was published for mgetty. CVE-2018-16741[0]: | An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, | the function do_activate() does