Bug#645325: CVE-2011-3378: Malformed Header parsing

2011-12-22 Thread Moritz Mühlenhoff
On Wed, Dec 21, 2011 at 06:02:09PM +, Jonathan Wiltshire wrote: > Dear maintainer, > > Recently you fixed one or more security problems and as a result you closed > this bug. These problems were not serious enough for a Debian Security > Advisory, so they are now on my radar for fixing in the

Bug#645325: CVE-2011-3378: Malformed Header parsing

2011-12-21 Thread Jonathan Wiltshire
Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.4) - use target

Bug#645325: CVE-2011-3378: Malformed Header parsing

2011-10-14 Thread Moritz Muehlenhoff
Package: rpm Severity: important Tags: security Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3378 and links to patches. Thanks to dpkg the attack vectors to a Debian system are rather limited, so I don't think this warrants a DSA. It could be fixed through a point update, tho