Bug#862167: jessie-pu: package polarssl/1.3.9-2.1+deb8u2

2017-05-27 Thread Adam D. Barratt
Control: tags -1 + pending On Tue, 2017-05-09 at 19:35 +0100, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Tue, 2017-05-09 at 11:42 +0100, James Cowgill wrote: > > This polarssl update fixes CVE-2017-2784 (Freeing of memory allocated on > > stack when validating a public key with

Processed: Re: Bug#862167: jessie-pu: package polarssl/1.3.9-2.1+deb8u2

2017-05-27 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + pending Bug #862167 [release.debian.org] jessie-pu: package polarssl/1.3.9-2.1+deb8u2 Added tag(s) pending. -- 862167: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862167 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Processed: Re: Bug#862167: jessie-pu: package polarssl/1.3.9-2.1+deb8u2

2017-05-09 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #862167 [release.debian.org] jessie-pu: package polarssl/1.3.9-2.1+deb8u2 Added tag(s) confirmed. -- 862167: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862167 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#862167: jessie-pu: package polarssl/1.3.9-2.1+deb8u2

2017-05-09 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2017-05-09 at 11:42 +0100, James Cowgill wrote: > This polarssl update fixes CVE-2017-2784 (Freeing of memory allocated on > stack when validating a public key with a secp224k1 curve) which is a > no-DSA security issue. > > I've tested the CVE with the

Bug#862167: jessie-pu: package polarssl/1.3.9-2.1+deb8u2

2017-05-09 Thread James Cowgill
Package: release.debian.org Severity: normal Tags: jessie User: release.debian@packages.debian.org Usertags: pu Hi, This polarssl update fixes CVE-2017-2784 (Freeing of memory allocated on stack when validating a public key with a secp224k1 curve) which is a no-DSA security issue. I've