Bug#1010264: CVE-2022-28391

2022-07-06 Thread Nobuhiro Iwamatsu
Package: busybox Version: 1:1.35.0-1 Tags: patch Followup-For: Bug #1010264 Dear Maintainer, I created a patch which corect this issue. The correction contained in this patch was taken from the following posts. http://lists.busybox.net/pipermail/busybox/2022-June/089751.html Could you check thi

Bug#1010264: Bug#1010263: Bug#1010264: CVE-2022-28391

2022-04-28 Thread Theodore Ts'o
On Thu, Apr 28, 2022 at 09:30:45AM +0200, Salvatore Bonaccorso wrote: > > Theodore, btw the BTS reference for the e2fsprogs issue is #1010263 > and the CVE id CVE-2022-1304. Yes, I've noted that already. > #1010264 and CVE-2022-28391 is respectively for busybox. the bug > already reassigned acco

Bug#1010264: CVE-2022-28391

2022-04-28 Thread Salvatore Bonaccorso
Hi, On Thu, Apr 28, 2022 at 09:04:52AM +0200, Moritz Muehlenhoff wrote: > On Wed, Apr 27, 2022 at 11:29:00PM -0400, Theodore Ts'o wrote: > > Neither seems to be security related. Are you sure this was correctly > > filed against e2fsprogs? > > Apologies, I reported multiple incoming new issues f

Bug#1010264: CVE-2022-28391

2022-04-28 Thread Moritz Muehlenhoff
On Wed, Apr 27, 2022 at 11:29:00PM -0400, Theodore Ts'o wrote: > Neither seems to be security related. Are you sure this was correctly > filed against e2fsprogs? Apologies, I reported multiple incoming new issues from the CVE feed and I must have mis-pasted the wrong Emacs buffer into the report.

Bug#1010264: CVE-2022-28391

2022-04-27 Thread Theodore Ts'o
On Wed, Apr 27, 2022 at 01:55:27PM +0200, Moritz Muehlenhoff wrote: > Package: e2fsprogs > Version: 1.46.5-2 > Severity: important > > This issue was found by Alpine: > https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661 > > Details and the patches they used are in the report above, but t