[Bug 1352421] Re: possible denial of service or code execution via integer overflow

2014-08-09 Thread Scott Kitterman
** Tags added: verification-done -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1352421 Title: possible denial of service or code execution via integer overflow To manage notifications about this bu

[Bug 1352421] Re: possible denial of service or code execution via integer overflow

2014-08-04 Thread Launchpad Bug Tracker
This bug was fixed in the package krfb - 4:4.13.0-0ubuntu1.1 --- krfb (4:4.13.0-0ubuntu1.1) trusty-security; urgency=medium * SECURITY UPDATE: denial of service or possible code execution via integer overflow in liblzo2 in libvncserver in krfb - debian/patches/upstream_libvn

[Bug 1352421] Re: possible denial of service or code execution via integer overflow

2014-08-04 Thread Marc Deslauriers
ACK on the trusty debdiff. Packages are building now and will be released today. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1352421 Title: possible denial of service or code execution via

[Bug 1352421] Re: possible denial of service or code execution via integer overflow

2014-08-04 Thread Jonathan Riddell
Fixed in trusty kubuntu-ppa updates PPA 4.13.3-0ubuntu1~ubuntu14.04~ppa1 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1352421 Title: possible denial of service or code execution via integer overflo

[Bug 1352421] Re: possible denial of service or code execution via integer overflow

2014-08-04 Thread Jonathan Riddell
** Patch added: "updated package" https://bugs.launchpad.net/ubuntu/+source/krfb/+bug/1352421/+attachment/4169647/+files/krfb_4.13.0-0ubuntu1.1.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs

[Bug 1352421] Re: possible denial of service or code execution via integer overflow

2014-08-04 Thread Jonathan Riddell
Fixed in utopic 4.13.97-0ubuntu2 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1352421 Title: possible denial of service or code execution via integer overflow To manage notifications about this bu

[Bug 1352421] Re: possible denial of service or code execution via integer overflow

2014-08-04 Thread Jonathan Riddell
Note the CVE is the same as the one for liblzo2 CVE-2014-4607 ** Also affects: krfb (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: krfb (Ubuntu Utopic) Importance: Undecided Status: New ** Changed in: krfb (Ubuntu Utopic) Status: New => Fix Released