Bug#929297: minissdpd: CVE-2019-12106

2019-05-27 Thread Chris Lamb
Hi Moritz, > > > Chris, thanks for your proposal to update Stretch, I very much > > > appreciate it. […] > This doesn't warrant a DSA, feel free to fix it via a point release instead. Sure thing. Proposed in #929613. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@d

Bug#929297: minissdpd: CVE-2019-12106

2019-05-26 Thread Moritz Mühlenhoff
On Sat, May 25, 2019 at 09:08:32AM +0100, Chris Lamb wrote: > Hey, > > > > The following vulnerability was published for minissdpd. > > > > > > CVE-2019-12106[0]: > > > | The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and > > > | 1.5 allows a remote attacker to crash the proce

Bug#929297: minissdpd: CVE-2019-12106

2019-05-25 Thread Chris Lamb
Hey, > > The following vulnerability was published for minissdpd. > > > > CVE-2019-12106[0]: > > | The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and > > | 1.5 allows a remote attacker to crash the process due to a Use After > > | Free vulnerability. […] > Chris, thanks for yo

Bug#929297: minissdpd: CVE-2019-12106

2019-05-22 Thread Chris Lamb
Hi, > > The following vulnerability was published for minissdpd. > > > > CVE-2019-12106[0]: > > | The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and > > | 1.5 allows a remote attacker to crash the process due to a Use After > > | Free vulnerability. […] > Chris, thanks for you

Bug#929297: minissdpd: CVE-2019-12106

2019-05-21 Thread Thomas Goirand
On 5/21/19 8:06 AM, Chris Lamb wrote: > Package: minissdpd > Version: 1.2.20130907-3+deb8u1 > X-Debbugs-CC: t...@security.debian.org > Severity: grave > Tags: security > > Hi, > > The following vulnerability was published for minissdpd. > > CVE-2019-12106[0]: > | The updateDevice function in min

Bug#929297: minissdpd: CVE-2019-12106

2019-05-20 Thread Chris Lamb
Hi, > minissdpd: CVE-2019-12106 Security team, would you like me to prepare an upload for stretch here? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#929297: minissdpd: CVE-2019-12106

2019-05-20 Thread Chris Lamb
Package: minissdpd Version: 1.2.20130907-3+deb8u1 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for minissdpd. CVE-2019-12106[0]: | The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and | 1.5 allows a remote a