Bug#704946: polarssl: CVE-2009-3555

2013-04-10 Thread Michael Gilbert
On Mon, Apr 8, 2013 at 4:00 AM, Roland Stigge wrote: At the polarssl's upstream tracker, I found the following similar issue: https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2011-01 regarding CVE-2011-1923 Is CVE-2011-1923 related to CVE-2009-3555? For

Bug#704946: polarssl: CVE-2009-3555

2013-04-10 Thread Roland Stigge
On 10/04/13 18:39, Michael Gilbert wrote: Is CVE-2011-1923 related to CVE-2009-3555? For CVE-2011-1923, they have a patch that applies to Debian's version in squeeze (fixed upstream in squeeze), which I can adapt easily and prepare as a security fix. Nothing found directly for CVE-2009-3555

Bug#704946: polarssl: CVE-2009-3555

2013-04-08 Thread Roland Stigge
Hi! Thanks for the note! On 04/08/2013 04:34 AM, Michael Gilbert wrote: This issue is still being tracked as affecting polarssl in the security tracker. It's old, so it's likely been fixed, but it's important to be thorough, so please check that it is and adjust the affected versions

Bug#704946: polarssl: CVE-2009-3555

2013-04-07 Thread Michael Gilbert
Package: polarssl Severity: important Tags: security Hi, This issue is still being tracked as affecting polarssl in the security tracker. It's old, so it's likely been fixed, but it's important to be thorough, so please check that it is and adjust the affected versions appropriately.