Bug#981553: CVE-2021-3156 backport for jessie

2021-02-28 Thread Bastian Germann
control: tag -1 - moreinfo Am 27.02.21 um 17:34 schrieb Hilko Bengen: Since LTS support for jessie ended on June 30, 2020, do you expect anything else to happen with these? I do not expect it. But as I fixed it for jessie and maybe there is someone out there who is interested, I provided the

Bug#981553: CVE-2021-3156 backport for jessie

2021-02-27 Thread Hilko Bengen
control: tag -1 moreinfo Bastian, thanks for providing the patches. Since LTS support for jessie ended on June 30, 2020, do you expect anything else to happen with these? Cheers, -Hilko

Bug#981553: CVE-2021-3156 backport for jessie

2021-02-01 Thread Bastian Germann
Package: sudo Severity: normal I have backported the applicable CVE-2021-3156 patches from stretch (1.8.19p1-2.1+deb9u3) to jessie. The patches are enclosed any apply on 1.8.10p3-1+deb8u7. From: "Todd C. Miller" Date: Wed, 20 Jan 2021 09:04:39 +0100 Subject: Don't assume that argv is allocated