Re: Fixing CVE-2017-5617 (SSRF) for svgsalamander in wheezy

2017-02-03 Thread Sebastiaan Couwenberg
On 02/03/2017 11:06 AM, Guido Günther wrote: > On Fri, Feb 03, 2017 at 10:07:55AM +0100, Sebastiaan Couwenberg wrote: >> Dear LTS Team, >> >> Vincent Privat of the JOSM development team have provided a fix for >> CVE-2017-5617 (#853134). >> >> I've included a patch with his changes in the Debian pa

Re: Fixing CVE-2017-5617 (SSRF) for svgsalamander in wheezy

2017-02-03 Thread Guido Günther
On Fri, Feb 03, 2017 at 10:07:55AM +0100, Sebastiaan Couwenberg wrote: > Dear LTS Team, > > Vincent Privat of the JOSM development team have provided a fix for > CVE-2017-5617 (#853134). > > I've included a patch with his changes in the Debian package, and > uploaded it to unstable, and backporte

Re: Fixing CVE-2017-5617 (SSRF) for svgsalamander

2017-02-03 Thread Sebastiaan Couwenberg
On 02/03/2017 10:13 AM, Moritz Muehlenhoff wrote: > On Fri, Feb 03, 2017 at 10:06:19AM +0100, Sebastiaan Couwenberg wrote: >> Fixed versions: >> >> * jessie: 0~svn95-1+deb8u1 >> * wheezy: 0~svn95-1+deb7u1 >> >> Are these changes OK for upload to security-master? > > Thanks. Please upload. Thank

Re: Fixing CVE-2017-5617 (SSRF) for svgsalamander

2017-02-03 Thread Moritz Muehlenhoff
On Fri, Feb 03, 2017 at 10:06:19AM +0100, Sebastiaan Couwenberg wrote: > Fixed versions: > > * jessie: 0~svn95-1+deb8u1 > * wheezy: 0~svn95-1+deb7u1 > > Are these changes OK for upload to security-master? Thanks. Please upload. Cheers, Moritz

Fixing CVE-2017-5617 (SSRF) for svgsalamander in wheezy

2017-02-03 Thread Sebastiaan Couwenberg
Dear LTS Team, Vincent Privat of the JOSM development team have provided a fix for CVE-2017-5617 (#853134). I've included a patch with his changes in the Debian package, and uploaded it to unstable, and backported the patch for the jessie & wheezy packages. Affected versions: * jessie: 0~svn95

Fixing CVE-2017-5617 (SSRF) for svgsalamander

2017-02-03 Thread Sebastiaan Couwenberg
Dear Security Team, Vincent Privat of the JOSM development team have provided a fix for CVE-2017-5617 (#853134). I've included a patch with his changes in the Debian package, and uploaded it to unstable, and backported the patch for the jessie & wheezy packages. Affected versions: * jessie: 0~

Re: CVE-2017-5617: svgSalamander

2017-02-03 Thread Sebastiaan Couwenberg
On 02/02/2017 07:09 PM, Sebastiaan Couwenberg wrote: > On 02/02/2017 07:44 AM, Sebastiaan Couwenberg wrote: >> On 02/01/2017 10:08 AM, Bas Couwenberg wrote: >>> On 2017-02-01 09:35, Bas Couwenberg wrote: Including the JOSM developers (josm-...@openstreetmap.org) is also a good idea, they