Bug#973963: RFS: libonig/6.9.6-1 -- regular expressions library

2021-02-06 Thread Adrian Bunk
On Sun, Nov 08, 2020 at 07:02:27PM +0100, Jörg Frings-Fürst wrote: > Hello Adrian, Hi Jörg, > CVE-2020-26159 was released following a review with Coverity. This resulted in > 27 errors. One of them was a false positive. > > Which of the bugs led to the CVE report I cannot judge. > > The

Bug#973963: RFS: libonig/6.9.6-1 -- regular expressions library

2020-11-08 Thread Jörg Frings-Fürst
Hello Adrian, CVE-2020-26159 was released following a review with Coverity. This resulted in 27 errors. One of them was a false positive. Which of the bugs led to the CVE report I cannot judge. The remaining bugs have been fixed in the meantime. I therefore believe that the CVE report can be

Bug#973963: RFS: libonig/6.9.6-1 -- regular expressions library

2020-11-08 Thread Adrian Bunk
Control: tags -1 moreinfo On Sun, Nov 08, 2020 at 01:19:46PM +0100, Jörg Frings-Fürst wrote: >... > Changes since the last upload: Looks good, except: >... >* New upstream release. >... > - Fix CVE-2020-26159 (Closes: #972113). >... What is the status of this CVE? If the comment in

Bug#973963: RFS: libonig/6.9.6-1 -- regular expressions library

2020-11-08 Thread Jörg Frings-Fürst
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "libonig": Package name: libonig Version : 6.9.6-1 Upstream Author : K.Kosako URL : https://github.com/kkos/oniguruma License : BSD-2-clause