Bug#870183: libgxps: CVE-2017-11590

2017-08-11 Thread Moritz Mühlenhoff
On Wed, Aug 09, 2017 at 10:24:48PM -0400, Jeremy Bicha wrote: > Control: forwarded -1 https://bugzilla.gnome.org/show_bug.cgi?id=785479 > > I have prepared packaging for unstable to fix this issue. I am a > Debian Maintainer and will need sponsoring. Would you be interested in > sponsoring this fo

Bug#870183: libgxps: CVE-2017-11590

2017-08-09 Thread Jeremy Bicha
Control: forwarded -1 https://bugzilla.gnome.org/show_bug.cgi?id=785479 I have prepared packaging for unstable to fix this issue. I am a Debian Maintainer and will need sponsoring. Would you be interested in sponsoring this for me? I have uploaded the packaging to https://mentors.debian.net/packa

Bug#870183: libgxps: CVE-2017-11590

2017-07-30 Thread Salvatore Bonaccorso
Source: libgxps Version: 0.2.5-1 Severity: important Tags: upstream security Hi, the following vulnerability was published for libgxps. CVE-2017-11590[0]: | There is a NULL pointer dereference in the caseless_hash function in | gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remo