[Pkg-javascript-devel] Bug#702261: libv8: CVE-2012-5153 CVE-2013-0836

2013-03-11 Thread Michael Gilbert
On Mon, Mar 4, 2013 at 10:39 AM, Moritz Muehlenhoff  wrote:
> Package: libv8
> Severity: grave
> Tags: security
> Justification: user security hole
>
> The previous Chrome release fixed two security issues in libv8:
>
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5153
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0836

These issues do not affect the current libv8 versions in debian.

Best wishes,
Mike

___
Pkg-javascript-devel mailing list
Pkg-javascript-devel@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-javascript-devel


[Pkg-javascript-devel] Bug#702261: libv8: CVE-2012-5153 CVE-2013-0836

2013-03-08 Thread Giuseppe Iuculano
On 04/03/2013 16:39, Moritz Muehlenhoff wrote:
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5153

Fix: https://code.google.com/p/v8/source/detail?r=13161


> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0836

Fix: https://code.google.com/p/v8/source/detail?r=12543


Cheers,
Giuseppe.



signature.asc
Description: OpenPGP digital signature
___
Pkg-javascript-devel mailing list
Pkg-javascript-devel@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-javascript-devel

[Pkg-javascript-devel] Bug#702261: libv8: CVE-2012-5153 CVE-2013-0836

2013-03-04 Thread Moritz Muehlenhoff
Package: libv8
Severity: grave
Tags: security
Justification: user security hole

The previous Chrome release fixed two security issues in libv8:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5153
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0836

It's probably best to contact upstream for specific commits.

Cheers,
Moritz

___
Pkg-javascript-devel mailing list
Pkg-javascript-devel@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-javascript-devel