Bug#954959: libunivalue: CVE-2019-18936

2020-03-26 Thread Jonas Smedegaard
Quoting Salvatore Bonaccorso (2020-03-26 16:09:56) > Hi Jonas, > > On Thu, Mar 26, 2020 at 03:19:45PM +0100, Jonas Smedegaard wrote: > > Quoting Salvatore Bonaccorso (2020-03-26 14:56:39) > > > Hey Jonas! > > > > > > [Cc'ing security team address] > > > > > > On Thu, Mar 26, 2020 at 12:13:34PM

Bug#954959: libunivalue: CVE-2019-18936

2020-03-26 Thread Salvatore Bonaccorso
Hi Jonas, On Thu, Mar 26, 2020 at 03:19:45PM +0100, Jonas Smedegaard wrote: > Quoting Salvatore Bonaccorso (2020-03-26 14:56:39) > > Hey Jonas! > > > > [Cc'ing security team address] > > > > On Thu, Mar 26, 2020 at 12:13:34PM +0100, Jonas Smedegaard wrote: > > > Quoting Salvatore Bonaccorso

Bug#954959: libunivalue: CVE-2019-18936

2020-03-26 Thread Jonas Smedegaard
Quoting Salvatore Bonaccorso (2020-03-26 14:56:39) > Hey Jonas! > > [Cc'ing security team address] > > On Thu, Mar 26, 2020 at 12:13:34PM +0100, Jonas Smedegaard wrote: > > Quoting Salvatore Bonaccorso (2020-03-25 21:07:13) > > > The following vulnerability was published for libunivalue. > > >

Bug#954959: libunivalue: CVE-2019-18936

2020-03-26 Thread Salvatore Bonaccorso
Hey Jonas! [Cc'ing security team address] On Thu, Mar 26, 2020 at 12:13:34PM +0100, Jonas Smedegaard wrote: > Quoting Salvatore Bonaccorso (2020-03-25 21:07:13) > > Source: libunivalue > > Version: 1.0.4-2 > > Severity: important > > Tags: security upstream > > Forwarded:

Bug#954959: libunivalue: CVE-2019-18936

2020-03-26 Thread Jonas Smedegaard
Quoting Salvatore Bonaccorso (2020-03-25 21:07:13) > Source: libunivalue > Version: 1.0.4-2 > Severity: important > Tags: security upstream > Forwarded: https://github.com/jgarzik/univalue/pull/58 > > Hi, > > The following vulnerability was published for libunivalue. > > CVE-2019-18936[0]: > |

Bug#954959: libunivalue: CVE-2019-18936

2020-03-25 Thread Salvatore Bonaccorso
Source: libunivalue Version: 1.0.4-2 Severity: important Tags: security upstream Forwarded: https://github.com/jgarzik/univalue/pull/58 Hi, The following vulnerability was published for libunivalue. CVE-2019-18936[0]: | UniValue::read() in UniValue before 1.0.5 allow attackers to cause a |