Bug#823893: libarchive: CVE-2016-1541

2016-05-16 Thread Simon McVittie
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, 16 May 2016 at 11:25:31 +0200, Andreas Henriksson wrote: > Please feel free to go ahead with NMU without delay (as already mentioned > to Salvatore)! Thanks, rescheduled to 0-day. > I'll focus on 3.2.0 myself which means I'll likely just ig

Bug#823893: libarchive: CVE-2016-1541

2016-05-16 Thread Andreas Henriksson
Hello Simon McVittie. On Mon, May 16, 2016 at 10:12:19AM +0100, Simon McVittie wrote: [...] > uploaded to DELAYED/5. Diff attached, or available here: > ssh://alioth.debian.org/srv/home/users/smcv/public_git/libarchive.git > > If you would like it accelerated or cancelled, please let me know; or

Bug#823893: libarchive: CVE-2016-1541

2016-05-16 Thread Simon McVittie
Control: tags 823893 + pending Control: tags 823984 + pending On Tue, 10 May 2016 at 09:18:26 +0200, Andreas Henriksson wrote: > I'm torn on uploading 3.2.0 to unstable now because of regressing on > kfreebsd where we now have test failures because of FTBFS. Feel free to > NMU to unstable as well

Bug#823893: libarchive: CVE-2016-1541

2016-05-12 Thread adam.jones
Hello Andreas, Has there been any news on this? Thank you, Adam

Bug#823893: libarchive: CVE-2016-1541

2016-05-10 Thread Andreas Henriksson
Hello Salvatore, On Tue, May 10, 2016 at 10:38:27AM +0200, Salvatore Bonaccorso wrote: > Hi Andreas, [...] > Makes sense then to wait for moving 3.2.0 to experimental. Thanks for > the ack on NMU'ing. I might then as well fix unstable with the > upstream patch. FYI I just sent a mail to inquiry a

Bug#823893: libarchive: CVE-2016-1541

2016-05-10 Thread Salvatore Bonaccorso
Hi Andreas, On Tue, May 10, 2016 at 09:18:26AM +0200, Andreas Henriksson wrote: > Hello Salvatore Bonaccorso. > > On Tue, May 10, 2016 at 08:12:48AM +0200, Salvatore Bonaccorso wrote: > > Hi, > > > > On Tue, May 10, 2016 at 06:34:05AM +0200, Salvatore Bonaccorso wrote: > > > Source: libarchive >

Bug#823893: libarchive: CVE-2016-1541

2016-05-10 Thread Andreas Henriksson
Hello Salvatore Bonaccorso. On Tue, May 10, 2016 at 08:12:48AM +0200, Salvatore Bonaccorso wrote: > Hi, > > On Tue, May 10, 2016 at 06:34:05AM +0200, Salvatore Bonaccorso wrote: > > Source: libarchive > > Version: 3.1.2-11 > > Severity: grave > > Tags: security upstream fixed-upstream > > Justifi

Bug#823893: libarchive: CVE-2016-1541

2016-05-09 Thread Salvatore Bonaccorso
Hi, On Tue, May 10, 2016 at 06:34:05AM +0200, Salvatore Bonaccorso wrote: > Source: libarchive > Version: 3.1.2-11 > Severity: grave > Tags: security upstream fixed-upstream > Justification: user security hole > Control: fixed -1 3.2.0-1 > > Hi, > > the following vulnerability was published for

Bug#823893: libarchive: CVE-2016-1541

2016-05-09 Thread Salvatore Bonaccorso
Source: libarchive Version: 3.1.2-11 Severity: grave Tags: security upstream fixed-upstream Justification: user security hole Control: fixed -1 3.2.0-1 Hi, the following vulnerability was published for libarchive. CVE-2016-1541[0]: | Heap-based buffer overflow in the zip_read_mac_metadata functi