Bug#786439: squeeze update of fuse?

2015-05-30 Thread Mike Gabriel
Hi László, hi Santiago, On Di 26 Mai 2015 21:33:01 CEST, László Böszörményi (GCS) wrote: Hi Santiago, On Tue, May 26, 2015 at 6:42 PM, Santiago Ruano Rincón wrote: Please find the attached dpatch to prevent CVE-2015-3202 in squeeze. It makes lib/mount_util.c use execle instead of execl to r

Bug#786439: squeeze update of fuse?

2015-05-27 Thread Raphael Hertzog
On Tue, 26 May 2015, László Böszörményi (GCS) wrote: > I can do it myself, I've the build system for Squeeze as well. My > only question if it should be an NMU or am I allowed to change the > maintainer? At least the former would be a bit strange for me as I'm > the actual maintainer, why should I

Bug#786439: squeeze update of fuse?

2015-05-26 Thread GCS
Hi Santiago, On Tue, May 26, 2015 at 6:42 PM, Santiago Ruano Rincón wrote: > Please find the attached dpatch to prevent CVE-2015-3202 in squeeze. It > makes lib/mount_util.c use execle instead of execl to run external > helpers. > > Please, let me know if you want me to upload a patched package,

Bug#786439: squeeze update of fuse?

2015-05-26 Thread Santiago Ruano Rincón
Hi Laszlo, Please find the attached dpatch to prevent CVE-2015-3202 in squeeze. It makes lib/mount_util.c use execle instead of execl to run external helpers. Please, let me know if you want me to upload a patched package, or if you want to do it by yourself. Cheers, Santiago #! /bin/sh /usr/sh

Bug#786439: squeeze update of fuse?

2015-05-22 Thread Raphael Hertzog
Control: found -1 2.8.4-1.1 Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of fuse: https://security-tracker.debian.org/tracker/CVE-2015-3202 Would you like to take care of this yourself? We are still understaff