Re: [Pkg-kde-extras] smb4k CVE-2017-8849

2017-06-15 Thread Markus Koschany
Hi Salvatore, Am 15.06.2017 um 05:53 schrieb Salvatore Bonaccorso: [...] > As confirmed by upstream (for the jessie-Version): > > cut-cut-cut-cut-cut-cut- > proc.setProgram( args["command"].toStringList() ); > > // Run the mount process. >

Re: [Pkg-kde-extras] smb4k CVE-2017-8849

2017-06-14 Thread Salvatore Bonaccorso
Hi Maximiliano and Markus, On Wed, Jun 14, 2017 at 12:51:04PM +0200, Maximiliano Curia wrote: > ¡Hola Salvatore! > > El 2017-06-13 a las 13:47 +0200, Salvatore Bonaccorso escribió: > > Thanks for analyzing the code for older versions. > > > On Mon, Jun 12, 2017 at 11:52:00PM +0200, Markus

Re: [Pkg-kde-extras] smb4k CVE-2017-8849

2017-06-14 Thread Maximiliano Curia
¡Hola Salvatore! El 2017-06-13 a las 13:47 +0200, Salvatore Bonaccorso escribió: Thanks for analyzing the code for older versions. On Mon, Jun 12, 2017 at 11:52:00PM +0200, Markus Koschany wrote: I had a look at smb4k and CVE-2017-8849 and wanted to mark the package in Wheezy and Jessie as

Re: [Pkg-kde-extras] smb4k CVE-2017-8849

2017-06-13 Thread Salvatore Bonaccorso
Hi Markus, Thanks for analyzing the code for older versions. On Mon, Jun 12, 2017 at 11:52:00PM +0200, Markus Koschany wrote: > Hi, > > I had a look at smb4k and CVE-2017-8849 and wanted to mark the package > in Wheezy and Jessie as not-affected. However I'm not completely sure > and I would