Re: imagemagick CVE-2016-4562, CVE-2016-4563, CVE-2016-4564

2016-06-11 Thread Brian May
Brian May writes: > Significant changes to TraceStrokePolygon function: Here is a diff ignoring white space changes: @@ -6021,13 +6022,25 @@ } if (q >= (ssize_t) (max_strokes-6*BezierQuantum-360)) { +if (~max_strokes < (6*BezierQuantum+360)) + { +p

Re: Wheezy update of roundcube?

2016-06-11 Thread Brian May
Markus Koschany writes: > I just had a closer look at the vulnerabilities. I have marked > CVE-2016-5103, CVE-2015-2181 and CVE-2015-2180 as not-affected because > the vulnerable code is not present in this version. There is no upstream > fix available for CVE-2016-4086. > > That leaves us with C

Wheezy update of spice?

2016-06-11 Thread Santiago Ruano Rincón
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of spice: https://security-tracker.debian.org/tracker/CVE-2016-2150 Please find attached a debdiff of a test package I have already prepared. You can also find it in