Re: [RFS] Patch to elasticsearch to fix CVS-2014-6439

2014-10-22 Thread Miguel Landaeta
Uploaded. Thanks.

-- 
Miguel Landaeta, nomadium at debian.org
secure email with PGP 0x6E608B637D8967E9 available at http://miguel.cc/key.
"Faith means not wanting to know what is true." -- Nietzsche


signature.asc
Description: Digital signature


Re: [RFS] Patch to elasticsearch to fix CVS-2014-6439

2014-10-20 Thread Miguel Landaeta
On Sun, Oct 19, 2014 at 10:30 PM, Tim Potter wrote:
> 
> Hi everyone.  I've pushed a patch to elasticsearch to fix a recent
> security vulnerability reported in a bug against the package.  Diff is
> attached.

Hi Tim,

Thanks for the patch. I'll review it and will upload the fix if
everything is OK.

Cheers,

-- 
Miguel Landaeta, nomadium at debian.org
secure email with PGP 0x6E608B637D8967E9 available at http://miguel.cc/key.
"Faith means not wanting to know what is true." -- Nietzsche


signature.asc
Description: Digital signature


[RFS] Patch to elasticsearch to fix CVS-2014-6439

2014-10-20 Thread Potter, Tim (Cloud Services)
Hi everyone.  I've pushed a patch to elasticsearch to fix a recent
security vulnerability reported in a bug against the package.  Diff is
attached.

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=763958

I've back-ported the fix from the master branch (sans tests as they don't
exist in 1.0.3).  Sorry also for the multiple commits.  I'm still
developing my workflow and local testing.

Could someone take a look and upload please?


Regards,

Tim.



CVE-2014-6439.patch
Description: Binary data


smime.p7s
Description: S/MIME cryptographic signature