Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-12 Thread Mike Gabriel
Hi Moritz, On Wednesday, 12 December 2018, Moritz Mühlenhoff wrote: > On Wed, Dec 12, 2018 at 03:46:10PM +, Mike Gabriel wrote: > > Hi Moritz, > > > > On Di 11 Dez 2018 22:15:33 CET, Moritz Mühlenhoff wrote: > > > > > On Tue, Dec 11, 2018 at 04:42:17PM +, Mike Gabriel wrote: > > > >

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-12 Thread Moritz Mühlenhoff
On Wed, Dec 12, 2018 at 03:46:10PM +, Mike Gabriel wrote: > Hi Moritz, > > On Di 11 Dez 2018 22:15:33 CET, Moritz Mühlenhoff wrote: > > > On Tue, Dec 11, 2018 at 04:42:17PM +, Mike Gabriel wrote: > > > From my understanding the potential remote code executions that are > > > mentioned

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-12 Thread Mike Gabriel
Hi Moritz, On Di 11 Dez 2018 22:15:33 CET, Moritz Mühlenhoff wrote: On Tue, Dec 11, 2018 at 04:42:17PM +, Mike Gabriel wrote: From my understanding the potential remote code executions that are mentioned in the CVE descriptions are triggered by a malign server and the code executions

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-11 Thread Jan Ingvoldstad
On 2018-12-11 22:15, Moritz Mühlenhoff wrote: On Tue, Dec 11, 2018 at 04:42:17PM +, Mike Gabriel wrote: From my understanding the potential remote code executions that are mentioned in the CVE descriptions are triggered by a malign server and the code executions then happen on the client

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-11 Thread Moritz Mühlenhoff
On Tue, Dec 11, 2018 at 04:42:17PM +, Mike Gabriel wrote: > From my understanding the potential remote code executions that are > mentioned in the CVE descriptions are triggered by a malign server and the > code executions then happen on the client side. Thanks for background. Security

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-11 Thread Antoine Beaupré
Gah. Forgot to fix the CC here as well, sorry for the noise. On 2018-12-11 10:05:53, Antoine Beaupré wrote: > On 2018-12-10 17:44:51, Mike Gabriel wrote: >> Hi, >> >> I'd like to discuss the possible pathways for getting FreeRDP fixed in >> Debian jessie LTS (and Debian stretch, too). >> >>

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-11 Thread Mike Gabriel
Hi Moritz, On Mo 10 Dez 2018 22:30:34 CET, Moritz Mühlenhoff wrote: On Mon, Dec 10, 2018 at 05:44:51PM +, Mike Gabriel wrote: Hi, I'd like to discuss the possible pathways for getting FreeRDP fixed in Debian jessie LTS (and Debian stretch, too). debian-security@ldo is not the proper

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-11 Thread Antoine Beaupré
On 2018-12-10 17:44:51, Mike Gabriel wrote: > Hi, > > I'd like to discuss the possible pathways for getting FreeRDP fixed in > Debian jessie LTS (and Debian stretch, too). > > Last week I talked to Bernhard Miklautz (one of the FreeRDP upsteam > maintainers and the actual packager of FreeRDPv2

Re: Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-10 Thread Moritz Mühlenhoff
On Mon, Dec 10, 2018 at 05:44:51PM +, Mike Gabriel wrote: > Hi, > > I'd like to discuss the possible pathways for getting FreeRDP fixed in > Debian jessie LTS (and Debian stretch, too). debian-security@ldo is not the proper contact address, I've fixed the recipient list. > Last week I

Addressing FreeRDP security issues in Debian jessie (and stretch)

2018-12-10 Thread Mike Gabriel
Hi, I'd like to discuss the possible pathways for getting FreeRDP fixed in Debian jessie LTS (and Debian stretch, too). Last week I talked to Bernhard Miklautz (one of the FreeRDP upsteam maintainers and the actual packager of FreeRDPv2 in Debian). 1. Looking at fixing FreeRDP v1.1 in