Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-06-05 Thread Chris Lamb
[adding 929...@bugs.debian.org to CC] Hi Moritz, > > Sure. Here's my updated patch: Uploaded zookeeper_3.4.9-3+deb9u2_amd64.changes to security-master. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-06-04 Thread tony mancill
On Fri, May 31, 2019 at 09:01:12AM +0200, Salvatore Bonaccorso wrote: > Hi Tony, > > On Thu, May 30, 2019 at 06:47:33AM -0700, tony mancill wrote: > > On Mon, May 27, 2019 at 10:07:38PM -0700, tony mancill wrote: > > > On Sun, May 26, 2019 at 08:58:29PM +0200, Moritz Mühlenhoff wrote: > > > >

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-06-04 Thread Chris Lamb
Hi Moritz, > > Thanks. Here is my diff: > > Looks fine, but can you please also include the test case upstream added? > Given that it's quite complex to reconstruct the specific affected ZK setup, > we should at least ship/run the test case. Sure. Here's my updated patch: diffstat for

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-05-31 Thread Salvatore Bonaccorso
Hi Tony, On Thu, May 30, 2019 at 06:47:33AM -0700, tony mancill wrote: > On Mon, May 27, 2019 at 10:07:38PM -0700, tony mancill wrote: > > On Sun, May 26, 2019 at 08:58:29PM +0200, Moritz Mühlenhoff wrote: > > > Looks fine, but can you please also include the test case upstream added? > > > Given

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-05-30 Thread tony mancill
On Mon, May 27, 2019 at 10:07:38PM -0700, tony mancill wrote: > On Sun, May 26, 2019 at 08:58:29PM +0200, Moritz Mühlenhoff wrote: > > Looks fine, but can you please also include the test case upstream added? > > Given that it's quite complex to reconstruct the specific affected ZK setup, > > we

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-05-27 Thread tony mancill
On Sun, May 26, 2019 at 08:58:29PM +0200, Moritz Mühlenhoff wrote: > On Fri, May 24, 2019 at 09:19:00AM +0100, Chris Lamb wrote: > > tags 929283 + patch > > thanks > > > > Hi Moritz, > > > > > > > zookeeper: CVE-2019-0201: information disclosure vulnerability > > > > > > > > Happy to prepare an

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-05-26 Thread Moritz Mühlenhoff
On Fri, May 24, 2019 at 09:19:00AM +0100, Chris Lamb wrote: > tags 929283 + patch > thanks > > Hi Moritz, > > > > > zookeeper: CVE-2019-0201: information disclosure vulnerability > > > > > > Happy to prepare an update for stretch; I plan to do one for jessie > > > LTS (which, helpfully, has the

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-05-24 Thread Chris Lamb
tags 929283 + patch thanks Hi Moritz, > > > zookeeper: CVE-2019-0201: information disclosure vulnerability > > > > Happy to prepare an update for stretch; I plan to do one for jessie > > LTS (which, helpfully, has the same version...) > > Sounds good, we should fix that in Stretch. I've just

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-05-23 Thread Moritz Mühlenhoff
On Thu, May 23, 2019 at 07:04:43AM +0100, Chris Lamb wrote: > [Adding t...@security.debian.org to CC] > > Hi, > > > zookeeper: CVE-2019-0201: information disclosure vulnerability > > Happy to prepare an update for stretch; I plan to do one for jessie > LTS (which, helpfully, has the same

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-05-23 Thread Chris Lamb
[Adding t...@security.debian.org to CC] Hi, > zookeeper: CVE-2019-0201: information disclosure vulnerability Happy to prepare an update for stretch; I plan to do one for jessie LTS (which, helpfully, has the same version...) Regards, -- ,''`. : :' : Chris Lamb `. `'`

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-05-20 Thread Salvatore Bonaccorso
Source: zookeeper Version: 3.4.13-1 Severity: grave Tags: security upstream Justification: user security hole Forwarded: https://issues.apache.org/jira/browse/ZOOKEEPER-1392 Control: found -1 3.4.9-3+deb9u1 Control: found -1 3.4.9-1 Hi, The following vulnerability was published for zookeeper.