Re: Thoughts on CVE-2020-15049/squid3?

2020-09-25 Thread Roberto C . Sánchez
On Fri, Sep 25, 2020 at 10:39:25PM +0200, Markus Koschany wrote: > > Yes, I have done the backport already but I wanted to wait for the > feedback of a user who reported another parsing issue in #965012. At the > moment I believe the current header parsing is correct but I am still > investigating

Re: Thoughts on CVE-2020-15049/squid3?

2020-09-25 Thread Markus Koschany
Am 25.09.20 um 22:24 schrieb Roberto C. Sánchez: > On Fri, Sep 25, 2020 at 10:04:59PM +0200, Markus Koschany wrote: >> Hello Roberto, >> >> Am 25.09.20 um 21:25 schrieb Roberto C. Sánchez: >>> Hello fellow LTS people, >>> >>> I am working on an update for the squid3 package. At this time there >>

Re: Thoughts on CVE-2020-15049/squid3?

2020-09-25 Thread Roberto C . Sánchez
On Fri, Sep 25, 2020 at 10:04:59PM +0200, Markus Koschany wrote: > Hello Roberto, > > Am 25.09.20 um 21:25 schrieb Roberto C. Sánchez: > > Hello fellow LTS people, > > > > I am working on an update for the squid3 package. At this time there > > are 4 open CVEs, of which 3 have patches that apply

Re: Thoughts on CVE-2020-15049/squid3?

2020-09-25 Thread Markus Koschany
Hello Roberto, Am 25.09.20 um 21:25 schrieb Roberto C. Sánchez: > Hello fellow LTS people, > > I am working on an update for the squid3 package. At this time there > are 4 open CVEs, of which 3 have patches that apply with little or no > change required. However, the patch for CVE-2020-15049 do

Thoughts on CVE-2020-15049/squid3?

2020-09-25 Thread Roberto C . Sánchez
Hello fellow LTS people, I am working on an update for the squid3 package. At this time there are 4 open CVEs, of which 3 have patches that apply with little or no change required. However, the patch for CVE-2020-15049 does not apply at all. Based on the commit message and an examination of the