Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

2017-08-12 Thread Simon McVittie
On Sat, 12 Aug 2017 at 15:33:34 +0200, Moritz Mühlenhoff wrote: > Feel free to simply upload an untested package for jessie-security, > I'm flying back on Sunday evening, I can run tests on jessie sometime > next week. I was able to do a smoke-test on a virtual machine (llvmpipe is much better

Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

2017-08-12 Thread Moritz Mühlenhoff
On Sat, Aug 12, 2017 at 01:46:33AM -0400, Simon McVittie wrote: > On Fri, 11 Aug 2017 at 20:11:46 +0200, Moritz Mühlenhoff wrote: > > Thanks, please upload. Generally speaking contrib is not supported, but > > it would be silly to fix ioquake, but not iortcw along, so please go ahead. > > Thanks,

Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

2017-08-11 Thread Simon McVittie
On Fri, 11 Aug 2017 at 20:11:46 +0200, Moritz Mühlenhoff wrote: > Thanks, please upload. Generally speaking contrib is not supported, but > it would be silly to fix ioquake, but not iortcw along, so please go ahead. Thanks, both uploaded to security-master targeting stretch-security. > What

Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

2017-08-11 Thread Moritz Mühlenhoff
On Thu, Aug 10, 2017 at 02:29:52PM -0400, Simon McVittie wrote: > On Sat, 05 Aug 2017 at 12:24:19 +0100, Simon McVittie wrote: > > Again, I don't have time to handle this for stable right now, so > > security or games team members are very welcome to do so. I'll prepare > > a stable update during

Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

2017-08-10 Thread Simon McVittie
On Sat, 05 Aug 2017 at 12:24:19 +0100, Simon McVittie wrote: > Again, I don't have time to handle this for stable right now, so > security or games team members are very welcome to do so. I'll prepare > a stable update during Debconf if nobody gets there first, assuming I > can find a stable user

Processed: Re: Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

2017-08-05 Thread Debian Bug Tracking System
Processing control commands: > clone -1 -2 Bug #870725 {Done: Simon McVittie <s...@debian.org>} [src:ioquake3] CVE-2017-11721: read buffer overflow in MSG_ReadBits Bug 870725 cloned as bug 870811 > reassign -2 src:iortcw Bug #870811 {Done: Simon McVittie <s...@debian.org>} [

Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

2017-08-05 Thread Simon McVittie
Control: clone -1 -2 Control: reassign -2 src:iortcw Control: forwarded -2 https://github.com/iortcw/iortcw/commit/260c39a29af517a08b3ee1a0e78ad654bdd70934 Control: found -2 1.51+dfsg1-2 Control: fixed -2 1.51+dfsg1-3 On Sat, 05 Aug 2017 at 11:47:23 +0100, Simon McVittie wrote: > On Fri, 04 Aug

Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

2017-08-05 Thread Simon McVittie
Control: retitle -1 CVE-2017-11721: read buffer overflow in MSG_ReadBits Control: tags -1 + upstream fixed-upstream patch Control: forwarded -1 https://github.com/ioquake/ioq3/commit/d2b1d124d4055c2fcbe5126863487c52fd58cca1 On Fri, 04 Aug 2017 at 16:30:46 +0200, Moritz Muehlenhoff wrote: >

Processed: Re: Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

2017-08-05 Thread Debian Bug Tracking System
Processing control commands: > retitle -1 CVE-2017-11721: read buffer overflow in MSG_ReadBits Bug #870725 {Done: Simon McVittie <s...@debian.org>} [src:ioquake3] CVE-2017-11721 Changed Bug title to 'CVE-2017-11721: read buffer overflow in MSG_ReadBits' from 'CVE-2017-11721'.