Re: [Secure-testing-team] Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-11 Thread Thorsten Glaser
Sébastien Delafond dixit: >Would you be able to produce debdiffs for jessie and stretch, so we can >review them and give you the go-ahead to upload to security-master ? OK, now that I’m waiting on the multi-hour testsuite results on sid. (It’s mostly that, due to the extra checks, the testsuite

Re: [Secure-testing-team] Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-11 Thread Thorsten Glaser
Sébastien Delafond dixit: >On Aug/11, Thorsten Glaser wrote: >> For {,{,old}old}stable-security, this should suffice: >> [...] > >Would you be able to produce debdiffs for jessie and stretch, so we can >review them and give you the go-ahead to upload to security-master ? Yes, although they’d

Re: [Secure-testing-team] Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-11 Thread Sébastien Delafond
On Aug/11, Thorsten Glaser wrote: > For {,{,old}old}stable-security, this should suffice: > [...] Would you be able to produce debdiffs for jessie and stretch, so we can review them and give you the go-ahead to upload to security-master ? Cheers, --Seb

Re: [Secure-testing-team] Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-11 Thread Thorsten Glaser
tags 871810 + patch pending thanks Salvatore Bonaccorso dixit: >Severity: grave Probably not as severe, the attack vector seems minimal. >[0] https://security-tracker.debian.org/tracker/CVE-2017-12836 >https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12836 >[1]