Bug#628456: [Pkg-erlang-devel] Bug#628456: Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Sergei Golovan
On Thu, Dec 29, 2011 at 4:05 PM, Luk Claes wrote: > Are you sure the Security Team thinks it does not warrant a DSA? I would > send the patch to the Security Team to see if they want to issue a DSA > or rather have it go via proposed-updates (in which case the patch > should be sent to the Release

Bug#628456: [Pkg-erlang-devel] Bug#628456: Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Luk Claes
On 12/29/2011 01:13 PM, Sergei Golovan wrote: > On Thu, Dec 29, 2011 at 4:05 PM, Luk Claes wrote: >> Are you sure the Security Team thinks it does not warrant a DSA? I would >> send the patch to the Security Team to see if they want to issue a DSA >> or rather have it go via proposed-updates (in w

Bug#628456: [Pkg-erlang-devel] Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Luk Claes
On 12/29/2011 12:38 PM, Sergei Golovan wrote: > Hi! > > On Thu, Dec 29, 2011 at 12:48 PM, Luk Claes wrote: >> Hi >> >> It looks like this bug still needs fixing in squeeze. I'm not sure what >> impact the VSN changes have in the upstream patch [1]. Can you have a >> look and maybe prepare and tes

Bug#628456: [Pkg-erlang-devel] Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Sergei Golovan
Hi! On Thu, Dec 29, 2011 at 12:48 PM, Luk Claes wrote: > Hi > > It looks like this bug still needs fixing in squeeze. I'm not sure what > impact the VSN changes have in the upstream patch [1]. Can you have a > look and maybe prepare and test a fixed package? I'm working on it. Will upload the fi

Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Luk Claes
Hi It looks like this bug still needs fixing in squeeze. I'm not sure what impact the VSN changes have in the upstream patch [1]. Can you have a look and maybe prepare and test a fixed package? Cheers Luk [1] https://github.com/erlang/otp/commit/f228601de45c5 -- To UNSUBSCRIBE, email to deb

Bug#628456: CVE-2011-0766: cryptographic weakness

2011-05-28 Thread Steffen Joeris
Package: erlang Severity: grave Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, Please see http://www.kb.cert.org/vuls/id/178990 for all the information. The upstream patch can be reviewed here: https://github.com/erlang/otp/commit/f228601de45c5 Cheers, Steffen -BEGIN PGP