[SECURITY] [DLA 1984-1] gdal security update

2019-11-09 Thread Utkarsh Gupta
Package: gdal Version: 1.10.1+dfsg-8+deb8u1 CVE ID : CVE-2019-17545 GDAL through 3.0.1 had a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold was exceeded. For Debian 8 "Jessie", this problem has been fixed in version

Re: RFS: gdal

2019-11-09 Thread Holger Levsen
Hi Utkarsh, On Sat, Nov 09, 2019 at 03:12:40PM +0530, Utkarsh Gupta wrote: > > thanks, looks good, upload in progress, should be there soon, at which > > I'll publish the DLA to lts-announce@. > Thank you very much! :D you're very welcome! > > Thanks, nice number! ;) Please also make sure to

Re: RFS: gdal

2019-11-09 Thread Utkarsh Gupta
Hi Holger, On 09/11/19 1:11 pm, Holger Levsen wrote: > Hi Utkarsh, > > On Thu, Nov 07, 2019 at 05:24:57PM +0530, Utkarsh Gupta wrote: >> Since I am still a DM, I'd heartily request to sponsor the upload of gdal. >> The package is tested and uploaded to mentors.d.net and the relevant >> .dsc could

RFS: ruby-haml

2019-11-09 Thread Utkarsh Gupta
Hey, I've fixed CVE-2017-1002201 and thus request for someone to sponsor the upload of ruby-haml. The package is tested and uploaded to mentors.d.net and the relevant .dsc could be found here[1]. I'm also attaching the DLA file for the same. Best, Utkarsh --- [1]: