Bug#1034190: More security bugs in game loading

2023-04-20 Thread Ben Hutchings
On Thu, 2023-04-20 at 10:01 +0200, Paul Gevers wrote: > Hi Ben, > > On Mon, 10 Apr 2023 22:01:04 +0200 Ben Hutchings > wrote: > > Package: sgt-puzzles > > Severity: serious > > The fix for this bug will not automatically migrate to testing because > the package doesn't have autopkgtests and we

Bug#1034190: More security bugs in game loading

2023-04-20 Thread Paul Gevers
Hi Ben, On Mon, 10 Apr 2023 22:01:04 +0200 Ben Hutchings wrote: Package: sgt-puzzles Severity: serious The fix for this bug will not automatically migrate to testing because the package doesn't have autopkgtests and we're in the freeze. The changes are massive, so I'd like to confirm in an

Bug#1034190: More security bugs in game loading

2023-04-10 Thread Ben Hutchings
Package: sgt-puzzles Version: 20230122.806ae71-1 Severity: serious Tags: security upstream fixed-upstream X-Debbugs-Cc: Debian Security Team Ben Harris found multiple issues in sgt-puzzles where a malformed game description or save file can lead to a buffer overflow, buffer overread, use of an un