Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-14 Thread Mike Hommey
On Sat, Dec 12, 2009 at 10:56:59PM -0500, Michael Gilbert wrote: package: xulrunner severity: serious tags: security Hi, The following CVE (Common Vulnerabilities Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and

Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-14 Thread Michael Gilbert
retitle 560946 xulrunner: embeds expat severity 560946 important thanks On Mon, 14 Dec 2009 09:15:12 +0100, Mike Hommey wrote: On Sat, Dec 12, 2009 at 10:56:59PM -0500, Michael Gilbert wrote: package: xulrunner severity: serious tags: security Hi, The following CVE (Common

Processed: Re: Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: retitle 560946 xulrunner: embeds expat Bug #560946 [xulrunner] CVE-2009-3560 and CVE-2009-3720 denial-of-services Changed Bug title to 'xulrunner: embeds expat' from 'CVE-2009-3560 and CVE-2009-3720 denial-of-services' severity 560946 important

Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: xulrunner severity: serious tags: security Hi, The following CVE (Common Vulnerabilities Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many