Bug#962221: Fixes for CVE-2020-13696 (#962221)

2020-07-08 Thread Mattia Rizzolo
On Wed, Jul 08, 2020 at 09:07:25AM +0100, Jeremy Sowden wrote: ... > The new upstream release added extra checks to ensure that the object at > the end of the path is a device file of the right sort before opening > it: ... > However, the error messages still leak information, allowing the user to

Bug#962221: Fixes for CVE-2020-13696 (#962221)

2020-07-08 Thread Jeremy Sowden
On 2020-07-06, at 19:11:09 +, Vasyl Gello wrote: > July 6, 2020 6:58:05 PM UTC, Mattia Rizzolo написав(-ла): > > On Mon, Jul 06, 2020 at 05:10:30AM +, Vasyl Gello wrote: > > > Thanks for contributing the security release! I checked your > > > changes and pushed them to the team repo. I do

Bug#962221: Fixes for CVE-2020-13696 (#962221)

2020-07-07 Thread Vasyl Gello
Mattia, July 7, 2020 2:42:20 PM UTC, Vasyl Gello написав(-ла): >Got it! OK, let me do a quick fix for both issues and push additional commit. Commit is pushed, please try rebuilding the package! --  Vasyl Gello == Certified SolidWorks Expert Mob.:

Bug#962221: Fixes for CVE-2020-13696 (#962221)

2020-07-07 Thread Vasyl Gello
Hi Mattia! July 7, 2020 2:25:37 PM UTC, Mattia Rizzolo написав(-ла): >..however it fails to build :) > > dh_auto_install > install -d /build/xawtv-3.107/debian/tmp > make -j4 install DESTDIR=/build/xawtv-3.107/debian/tmp > AM_UPDATE_INFO_DIR=no >make[1]: Entering directory '/build/

Bug#962221: Fixes for CVE-2020-13696 (#962221)

2020-07-07 Thread Mattia Rizzolo
On Mon, Jul 06, 2020 at 09:07:31PM +, Vasyl Gello wrote: > I pushed the modernized package however ..however it fails to build :) dh_auto_install install -d /build/xawtv-3.107/debian/tmp make -j4 install DESTDIR=/build/xawtv-3.107/debian/tmp AM_UPDATE_INFO_DIR=no make[1]:

Bug#962221: Fixes for CVE-2020-13696 (#962221)

2020-07-06 Thread Vasyl Gello
Hi Mattia! July 6, 2020 6:58:05 PM UTC, Mattia Rizzolo написав(-ла): >but could either of you do a bunch of housekeeping work as well, like: > * bumping dh compat > * drop --dbgsym-migration > * drop the .menu files > * would be awesome to have the copyright file rewrote using dep-5 > * I p

Bug#962221: Fixes for CVE-2020-13696 (#962221)

2020-07-06 Thread Vasyl Gello
Hi Mattia! By partial I understood that upstream fixed the core part but the Debian patch sjould have been adapted to reflect new changes. Jeremy, can you please correct me if I am wrong? --  Vasyl Gello == Certified SolidWorks Expert Mob.:+380 (98

Bug#962221: Fixes for CVE-2020-13696 (#962221)

2020-07-06 Thread Mattia Rizzolo
On Mon, Jul 06, 2020 at 05:10:30AM +, Vasyl Gello wrote: > Thanks for contributing the security release! I checked your changes and > pushed them to the team repo. > I do not have an upload rights, so CCing Sebastian and Mattia. Sure, but could either of you do a bunch of housekeeping work a

Bug#962221: Fixes for CVE-2020-13696 (#962221)

2020-07-05 Thread Vasyl Gello
Hi Jeremy! Thanks for contributing the security release! I checked your changes and pushed them to the team repo. I do not have an upload rights, so CCing Sebastian and Mattia. --  Vasyl Gello == Certified SolidWorks Expert Mob.:+380 (98) 465 66 77