Bug#819050: Please leave the severity at serious, this bug is a security issue.

2016-03-25 Thread Salvatore Bonaccorso
Hi Hilko, On Fri, Mar 25, 2016 at 07:48:42PM +0100, Hilko Bengen wrote: > * Salvatore Bonaccorso: > > > Can you confirm that the packages at > > https://people.debian.org/~carnil/tmp/pcre3/jessie/ fix as well the > > case reported in #819050? The package at above link contain the > > proposed fix

Bug#819050: Please leave the severity at serious, this bug is a security issue.

2016-03-25 Thread Hilko Bengen
* Salvatore Bonaccorso: > Can you confirm that the packages at > https://people.debian.org/~carnil/tmp/pcre3/jessie/ fix as well the > case reported in #819050? The package at above link contain the > proposed fixes which I submitted for the next Jessie point release and > on top of it r1475 commi

Bug#819050: Please leave the severity at serious, this bug is a security issue.

2016-03-25 Thread Salvatore Bonaccorso
Hi all, On Fri, Mar 25, 2016 at 08:18:34AM +0100, Pierre Chifflier wrote: > On 03/24/2016 09:38 AM, Yves-Alexis Perez wrote: > > control: affects -1 suricata > > On jeu., 2016-03-24 at 07:20 +0100, Florian Weimer wrote: > >> * Hilko Bengen: > >> > >>> > >>> the original report may not have been 10

Bug#819050: Please leave the severity at serious, this bug is a security issue.

2016-03-25 Thread Pierre Chifflier
On 03/24/2016 09:38 AM, Yves-Alexis Perez wrote: > control: affects -1 suricata > On jeu., 2016-03-24 at 07:20 +0100, Florian Weimer wrote: >> * Hilko Bengen: >> >>> >>> the original report may not have been 100% clear on this, but the bug is >>> the main cause of a vulnerability in Suricata (a net

Bug#819050: Please leave the severity at serious, this bug is a security issue.

2016-03-24 Thread Yves-Alexis Perez
control: affects -1 suricata On jeu., 2016-03-24 at 07:20 +0100, Florian Weimer wrote: > * Hilko Bengen: > > > > > the original report may not have been 100% clear on this, but the bug is > > the main cause of a vulnerability in Suricata (a network IDS/IPS) that > > allows for remote denial of se

Bug#819050: Please leave the severity at serious, this bug is a security issue.

2016-03-24 Thread Florian Weimer
* Hilko Bengen: > the original report may not have been 100% clear on this, but the bug is > the main cause of a vulnerability in Suricata (a network IDS/IPS) that > allows for remote denial of service, possibly remote code execution by > simply passing crafted packets by a Suricata installation.

Bug#819050: Please leave the severity at serious, this bug is a security issue.

2016-03-23 Thread Hilko Bengen
control: tag -1 security control: severity -1 serious Hi Matthew, the original report may not have been 100% clear on this, but the bug is the main cause of a vulnerability in Suricata (a network IDS/IPS) that allows for remote denial of service, possibly remote code execution by simply passing c