Re: ImageMagick - marking issue as not affecting wheezy?

2016-10-28 Thread Roberto C . Sánchez
On Fri, Oct 28, 2016 at 09:41:42AM -0400, Antoine Beaupré wrote: > On 2016-10-28 07:53:39, Roberto C. Sánchez wrote: > > It appears to me that the upstream diff is ensuring that the allocated > > memory area is not too small, hence the change of "number_planes_filled" > > to "MagickMax(number_plane

Re: ImageMagick - marking issue as not affecting wheezy?

2016-10-28 Thread Antoine Beaupré
On 2016-10-28 07:53:39, Roberto C. Sánchez wrote: > It appears to me that the upstream diff is ensuring that the allocated > memory area is not too small, hence the change of "number_planes_filled" > to "MagickMax(number_planes_filled,4)" in two places. However, in the > code currently in wheezy,

Re: ImageMagick - marking issue as not affecting wheezy?

2016-10-28 Thread Roberto C . Sánchez
On Fri, Oct 28, 2016 at 09:28:37AM -0400, Antoine Beaupré wrote: > On 2016-10-27 22:28:17, Roberto C. Sánchez wrote: > > [ Unknown signature status ] > > Hello, > > > > I decided (perhaps because I don't know any better) to take over > > ImageMagick after Ben released his lock on it. > > For the r

Re: ImageMagick - marking issue as not affecting wheezy?

2016-10-28 Thread Antoine Beaupré
On 2016-10-27 22:28:17, Roberto C. Sánchez wrote: > [ Unknown signature status ] > Hello, > > I decided (perhaps because I don't know any better) to take over > ImageMagick after Ben released his lock on it. For the record, I did the same yesterday, except I forgot to lock the package... :/ I hav

Re: ImageMagick - marking issue as not affecting wheezy?

2016-10-28 Thread Roberto C . Sánchez
On Thu, Oct 27, 2016 at 10:28:17PM -0400, Roberto C. Sánchez wrote: > > I have some questions about how to handle this issue: > > https://security-tracker.debian.org/tracker/TEMP-0836171-53B142 > https://bugs.debian.org/836171 > So, I have another similar issue on which I would like some confi

Re: ImageMagick - marking issue as not affecting wheezy?

2016-10-28 Thread Roberto C . Sánchez
Hi Raphael, Thanks for the feedback. On Fri, Oct 28, 2016 at 10:32:06AM +0200, Raphael Hertzog wrote: > Hi, > > On Thu, 27 Oct 2016, Roberto C. Sánchez wrote: > > https://security-tracker.debian.org/tracker/TEMP-0836171-53B142 > > https://bugs.debian.org/836171 > > > > The diff that addresses t

Re: ImageMagick - marking issue as not affecting wheezy?

2016-10-28 Thread Raphael Hertzog
Hi, On Thu, 27 Oct 2016, Roberto C. Sánchez wrote: > https://security-tracker.debian.org/tracker/TEMP-0836171-53B142 > https://bugs.debian.org/836171 > > The diff that addresses this issue is here: > https://github.com/ImageMagick/ImageMagick/commit/10b3823a7619ed22d42764733eb052c4159bc8c1 This

ImageMagick - marking issue as not affecting wheezy?

2016-10-27 Thread Roberto C . Sánchez
Hello, I decided (perhaps because I don't know any better) to take over ImageMagick after Ben released his lock on it. I have some questions about how to handle this issue: https://security-tracker.debian.org/tracker/TEMP-0836171-53B142 https://bugs.debian.org/836171 The diff that addresses thi