Bug#814030: CVE-2017-6100: Security flaw fixed in version 6.2.0

2017-04-19 Thread Raphael Hertzog
On Tue, 18 Apr 2017, Moritz Mühlenhoff wrote: > > Moritz/Salvatore, do you want this in jessie-proposed-updates or in > > jessie-security? > > Please fix these via the upcoming jessie point update. Ok. Laurent, can you file a bug against "release.debian.org" to ask for permission to upload a sta

Bug#814030: CVE-2017-6100: Security flaw fixed in version 6.2.0

2017-04-18 Thread Moritz Mühlenhoff
On Tue, Apr 18, 2017 at 05:04:15PM +0200, Raphael Hertzog wrote: > Hello everybody, > > On Sat, 14 Jan 2017, Moritz Mühlenhoff wrote: > > > The upstream bug is now public: > > > https://sourceforge.net/p/tcpdf/bugs/1005/ > > > > Since K_TCPDF_CALLS_IN_HTML defaults to true in jessie, we should fi

Bug#814030: CVE-2017-6100: Security flaw fixed in version 6.2.0

2017-04-18 Thread Raphael Hertzog
Hello everybody, On Sat, 14 Jan 2017, Moritz Mühlenhoff wrote: > > The upstream bug is now public: > > https://sourceforge.net/p/tcpdf/bugs/1005/ > > Since K_TCPDF_CALLS_IN_HTML defaults to true in jessie, we should fix > this in jessie. > > Could someone of the maintainers prepare an update? L