[Bug 1743762] Re: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

2018-02-05 Thread Marc Deslauriers
I am unsubscribing ubuntu-security-sponsors for now since there is no artful debdiff to review. Please subscribe ubuntu-security-sponsors again once an appropriate debdiff is available. Thanks! ** Changed in: xmltooling (Ubuntu Bionic) Status: Triaged => Fix Released -- You received this

[Bug 1743762] Re: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

2018-01-17 Thread Launchpad Bug Tracker
This bug was fixed in the package xmltooling - 1.5.6-2ubuntu0.1 --- xmltooling (1.5.6-2ubuntu0.1) xenial-security; urgency=medium * SECURITY UPDATE: Upstream patch to fix CVE-2018-0486 (LP: #1743762) - d/p/CVE-2018-0486-Block-entity-reference-nodes-during-unmarshalling.patch:

[Bug 1743762] Re: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

2018-01-17 Thread Launchpad Bug Tracker
This bug was fixed in the package xmltooling - 1.5.3-2+deb8u2build0.14.04.1 --- xmltooling (1.5.3-2+deb8u2build0.14.04.1) trusty-security; urgency=medium * fake sync from Debian (LP: #1743762) xmltooling (1.5.3-2+deb8u2) jessie-security; urgency=high * [5c2845b] Add gbp.conf

[Bug 1743762] Re: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

2018-01-17 Thread Ubuntu Foundations Team Bug Bot
The attachment "CVE-2018-0486.debdiff" seems to be a debdiff. The ubuntu-sponsors team has been subscribed to the bug report so that they can review and hopefully sponsor the debdiff. If the attachment isn't a patch, please remove the "patch" flag from the attachment, remove the "patch" tag, and

[Bug 1743762] Re: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

2018-01-17 Thread Bert Van de Poel
Debian is working on patches for all of its stable repositories. See https://lists.alioth.debian.org/pipermail/pkg-shibboleth- devel/2018-January/thread.html for details. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1743762] Re: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

2018-01-17 Thread Ray Link
Here's a debdiff for Xenial. It is my understanding that Trusty can get a fakesync from Jessie. ** Patch added: "CVE-2018-0486.debdiff" https://bugs.launchpad.net/ubuntu/+source/xmltooling/+bug/1743762/+attachment/5038524/+files/CVE-2018-0486.debdiff -- You received this bug notification

[Bug 1743762] Re: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

2018-01-17 Thread Steve Beattie
** Also affects: xmltooling (Ubuntu Bionic) Importance: Undecided Status: Triaged ** Also affects: xmltooling (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: xmltooling (Ubuntu Xenial) Importance: Undecided Status: New ** Also affects: xmltooling

[Bug 1743762] Re: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

2018-01-17 Thread Steve Beattie
** Changed in: xmltooling (Ubuntu) Status: Incomplete => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1743762 Title: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486] To

[Bug 1743762] Re: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

2018-01-17 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1743762] Re: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486]

2018-01-17 Thread Hans Joachim Desserud
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-0486 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1743762 Title: Security bug in XMLTooling-C before 1.6.3 [CVE-2018-0486] To