Re: [Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] add python2.6, 2.7 and claim 2.7

2018-02-07 Thread Brian May
Abhijith PA writes: >> Do you have any objections to marking python2.6 and python2.7 as no-DSA >> in wheezy too? > > No, I don't have any objection. :) > I tried to reproduce this CVE with the given POC from upstream bug > report. But 8 out of 10 I didn't see any. As security team already > marke

Re: [Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] add python2.6, 2.7 and claim 2.7

2018-02-06 Thread Abhijith PA
Hi, On Wednesday 07 February 2018 12:54 PM, Brian May wrote: > > Hello, > > I see you have claimed Python2.7 but not Python2.6, which both have the > same vulnerability. CVE-2018-130 > > Upstream have decided that this is not a security issue, and it has been > marked no-DSA in Jessie and S

Re: [Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] add python2.6, 2.7 and claim 2.7

2018-02-06 Thread Brian May
Abhijith PA writes: > +python2.6 > +-- > +python2.7 (Abhijith PA) > +-- Hello, I see you have claimed Python2.7 but not Python2.6, which both have the same vulnerability. CVE-2018-130 Upstream have decided that this is not a security issue, and it has been marked no-DSA in Jessie and Stre