Bug#927378: stretch-pu: package node-superagent/0.20.0+dfsg-1+deb9u1

2019-04-22 Thread Adam D. Barratt
On Tue, 2019-04-23 at 07:10 +0200, Xavier wrote: > Le 23/04/2019 à 07:02, Adam D. Barratt a écrit : > > On Mon, 2019-04-22 at 23:17 +0200, Xavier wrote: > > > Le 22/04/2019 à 20:15, Paul Gevers a écrit : > > > > [...] > > > > I think your patch seems to be invalid in stretch. When I ran > > > >

Bug#927378: stretch-pu: package node-superagent/0.20.0+dfsg-1+deb9u1

2019-04-22 Thread Xavier
Le 23/04/2019 à 07:02, Adam D. Barratt a écrit : > On Mon, 2019-04-22 at 23:17 +0200, Xavier wrote: >> Le 22/04/2019 à 20:15, Paul Gevers a écrit : > [...] >>> I think your patch seems to be invalid in stretch. When I ran the >>> autopkgtests in stretch I see the error below, which is exactly the

Bug#927378: stretch-pu: package node-superagent/0.20.0+dfsg-1+deb9u1

2019-04-22 Thread Adam D. Barratt
On Mon, 2019-04-22 at 23:17 +0200, Xavier wrote: > Le 22/04/2019 à 20:15, Paul Gevers a écrit : [...] > > I think your patch seems to be invalid in stretch. When I ran the > > autopkgtests in stretch I see the error below, which is exactly the > > new code. [...] > sorry for this error in my

Bug#927378: stretch-pu: package node-superagent/0.20.0+dfsg-1+deb9u1

2019-04-22 Thread Xavier
Le 22/04/2019 à 20:15, Paul Gevers a écrit : > Hi Xavier, > > On Thu, 18 Apr 2019 20:44:01 +0200 Xavier Guimard wrote: >> I updated node-superagent for Buster. Now I would like to propose the >> security fix for stretch. This fixes CVE-2017-16129 (ZIP bomb attacks). > > I think your patch seems

Bug#927378: stretch-pu: package node-superagent/0.20.0+dfsg-1+deb9u1

2019-04-22 Thread Paul Gevers
Hi Xavier, On Thu, 18 Apr 2019 20:44:01 +0200 Xavier Guimard wrote: > I updated node-superagent for Buster. Now I would like to propose the > security fix for stretch. This fixes CVE-2017-16129 (ZIP bomb attacks). I think your patch seems to be invalid in stretch. When I ran the autopkgtests in

Bug#927378: stretch-pu: package node-superagent/0.20.0+dfsg-1+deb9u1

2019-04-20 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2019-04-18 at 20:44 +0200, Xavier Guimard wrote: > I updated node-superagent for Buster. Now I would like to propose the > security fix for stretch. This fixes CVE-2017-16129 (ZIP bomb > attacks). ++if (buffer) { ++  // Protectiona against zip

Bug#927378: stretch-pu: package node-superagent/0.20.0+dfsg-1+deb9u1

2019-04-18 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Hi all, I updated node-superagent for Buster. Now I would like to propose the security fix for stretch. This fixes CVE-2017-16129 (ZIP bomb attacks). Cheers, Xavier diff --git