Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-30 Thread Guillem Jover
On Wed, 2014-04-30 at 14:45:36 +0200, Raphael Geissert wrote: > On 30 April 2014 01:36, Guillem Jover wrote: > [...] > > Attached a non-tested quick patch implementing this. I'll start > > testing it and preparing packages for all suites. > > In case you were waiting for an ACK, please go ahead.

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-30 Thread Raphael Geissert
Hi Guillem, On 30 April 2014 01:36, Guillem Jover wrote: [...] > Attached a non-tested quick patch implementing this. I'll start > testing it and preparing packages for all suites. In case you were waiting for an ACK, please go ahead. I'll handle the update soon after they've hit the sec archive

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-29 Thread Guillem Jover
Hi! On Wed, 2014-04-30 at 00:12:56 +0200, Jakub Wilk wrote: > * Guillem Jover , 2014-04-29, 23:40: > >>>1. Simply revert the patch, and ignore issues w/ partial upgrades (at > >>>least for now?). > >>>2. Revert the patch and add versioned depdendencies against the > >>>working patch package. This

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-29 Thread Jakub Wilk
* Guillem Jover , 2014-04-29, 23:40: 1. Simply revert the patch, and ignore issues w/ partial upgrades (at least for now?). 2. Revert the patch and add versioned depdendencies against the working patch package. This might require some dist-upgrade tests, though. 3. Fix the patch to take into ac

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-29 Thread Guillem Jover
On Tue, 2014-04-29 at 18:55:35 +0200, Jakub Wilk wrote: > * Guillem Jover , 2014-04-29, 08:11: > >1. Simply revert the patch, and ignore issues w/ partial upgrades (at > >least for now?). > >2. Revert the patch and add versioned depdendencies against the working > >patch package. This might require

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-29 Thread Jakub Wilk
* Guillem Jover , 2014-04-29, 08:11: 1. Simply revert the patch, and ignore issues w/ partial upgrades (at least for now?). 2. Revert the patch and add versioned depdendencies against the working patch package. This might require some dist-upgrade tests, though. 3. Fix the patch to take into acc

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-29 Thread Sven Joachim
On 2014-04-29 12:27 +0200, Raphael Geissert wrote: > On 29 April 2014 08:11, Guillem Jover wrote: > [...] >> 2. Revert the patch and add versioned depdendencies against the working >> patch package. This might require some dist-upgrade tests, though. >> 3. Fix the patch to take into acco

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-29 Thread Raphael Geissert
Hi, On 29 April 2014 08:11, Guillem Jover wrote: [...] > 2. Revert the patch and add versioned depdendencies against the working > patch package. This might require some dist-upgrade tests, though. > 3. Fix the patch to take into account the old behaviour, by checking > if either of

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-28 Thread Guillem Jover
Hi, On Mon, 2014-04-28 at 22:35:57 +0200, Javier Serrano Polo wrote: > Package: dpkg > Version: 1.15.9 > Tags: security squeeze > As far as I see, escaping file names was added to diffutils in 2012. The > feature is not present in a squeeze environment. CVE-2014-0471 does not > apply. > > Direct