Bug#914381: libsndfile: CVE-2018-19432

2019-08-16 Thread Petter Reinholdtsen
[Erik de Castro Lopo] > You need to ask the debian people as they are the ones that apply > patches to my releases. This is what I am trying to do, using the sensible mechanism (the bug tracking system). Is there a new release of libsndfile with all security fixes available? Will a simple update

Bug#914381: libsndfile: CVE-2018-19432

2019-08-16 Thread Erik de Castro Lopo
Petter Reinholdtsen wrote: > According to https://security-tracker.debian.org/tracker/CVE-2018-19432 > >, > this security issue is only fixed in the jessie (oldoldstable) security > repository. Why is it not fixed in unstable, stable and oldstable? YOu need to ask the debian people as they are

Bug#914381: libsndfile: CVE-2018-19432

2019-08-16 Thread Petter Reinholdtsen
According to https://security-tracker.debian.org/tracker/CVE-2018-19432 >, this security issue is only fixed in the jessie (oldoldstable) security repository. Why is it not fixed in unstable, stable and oldstable? -- Happy hacking Petter Reinholdtsen

Bug#914381: libsndfile: CVE-2018-19432

2019-01-02 Thread Salvatore Bonaccorso
Control: tags -1 + fixed-upstream On Thu, Nov 22, 2018 at 09:19:57PM +0100, Salvatore Bonaccorso wrote: > Source: libsndfile > Version: 1.0.28-4 > Severity: important > Tags: security upstream > Forwarded: https://github.com/erikd/libsndfile/issues/427 > > Hi, > > The following vulnerability

Bug#914381: libsndfile: CVE-2018-19432

2018-11-22 Thread Salvatore Bonaccorso
Source: libsndfile Version: 1.0.28-4 Severity: important Tags: security upstream Forwarded: https://github.com/erikd/libsndfile/issues/427 Hi, The following vulnerability was published for libsndfile. CVE-2018-19432[0]: | An issue was discovered in libsndfile 1.0.28. There is a NULL pointer |