Re: xdelta, grave bug 147187, time left

2007-01-19 Thread LaMont Jones
On Thu, Jan 18, 2007 at 05:37:26PM -0800, Steve Langasek wrote: On Sat, Jan 13, 2007 at 11:28:11AM +0100, A Mennucc wrote: So the question to d-release team (and to the mantainer) is: should/could I NMU a new version with this patch applied? That question isn't one the release team really

Re: xdelta, grave bug 147187, time left

2007-01-19 Thread Steve Langasek
On Sat, Jan 13, 2007 at 11:28:11AM +0100, A Mennucc wrote: this bug's severity was debated a lot; in the end , it was decide to downgrade it fast forward to today: since I would need to use xdelta across 32bit and 64bit archs (see

Re: xdelta, grave bug 147187, time left

2007-01-19 Thread A Mennucc
On Thu, Jan 18, 2007 at 09:03:16PM -0700, LaMont Jones wrote: I hadn't seen the mail that added the patch to the bug report - I'll work on xdelta this weekend. that patch should fix interoperability between 64 and 32 bit I dont know if it addresses security implications... thanks thank you

xdelta, grave bug 147187, time left

2007-01-13 Thread A Mennucc
hi xdelta is affected by bug 147187 this is Steve Langasek analysis: the problem was that the xdelta file format includes information telling xdelta how much memory it needs to allocate in order to read in the patch structure -- and when allocating space for objects that include pointers, this