Re: tiff / tiff3 / CVE-2015-7554 / CVE-2016-5318

2016-09-15 Thread Brian May
Raphael Hertzog writes: >> What does the TIFFReadDirectoryFindFieldInfo function do? What >> situations is TIFFReadDirectoryFindFieldInfo unsuccessful? > > I don't know. It searches for the field in the tiff file. As I guessed. Which confused me (and still does), if the field is not there, how

Re: [Secure-testing-commits] r44612 - data/CVE

2016-09-15 Thread Moritz Mühlenhoff
On Thu, Sep 15, 2016 at 04:13:52PM +, Markus Koschany wrote: > Author: apo > Date: 2016-09-15 16:13:52 + (Thu, 15 Sep 2016) > New Revision: 44612 > > Modified: >data/CVE/list > Log: > mantis: CVE-2016-6837, no-dsa, unsupported > > > Modified: data/CVE/list > =

Wheezy update of dropbear?

2016-09-15 Thread Markus Koschany
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of dropbear: https://security-tracker.debian.org/tracker/CVE-2016-7406 https://security-tracker.debian.org/tracker/CVE-2016-7407 https://security-tracker.debian.org/tr

Re: updates to find-work

2016-09-15 Thread Chris Lamb
Hi Brian, > If not, does anybody have any objections if I were to commit the > following change? It adds a --unassigned command line option that only > lists packages that are not taken by anybody. I've just added an optional feature whereby, for example: $ ./find-work --unassigned="Chris Lamb

Re: MySQL 5.5.52 update for Debian wheezy?

2016-09-15 Thread Roberto C . Sánchez
On Thu, Sep 15, 2016 at 06:22:14AM -0700, Lars Tangvald wrote: > Hi, > > Yes, sorry I didn't communicate what I was doing. I've built and tested the > package I uploaded to git, for both Wheezy and Jessie, but I think that's as > far as I can take it. > When I've done work on the security update

Re: MySQL 5.5.52 update for Debian wheezy?

2016-09-15 Thread Lars Tangvald
Hi, Yes, sorry I didn't communicate what I was doing. I've built and tested the package I uploaded to git, for both Wheezy and Jessie, but I think that's as far as I can take it. When I've done work on the security updates before, at this stage I've simply sent a debdiff over to the security te

Re: Questions regarding MySQL update

2016-09-15 Thread Roberto C . Sánchez
On Wed, Sep 14, 2016 at 09:07:32AM -0400, Roberto C. Sánchez wrote: > > That is not to say that they couldn't have addressed the vulnerabilities > without contacting David to tell him that they had done say. That said, > the exploit is explained in a very detailed and methodical way in the > advi

MySQL 5.5.52 update for Debian wheezy?

2016-09-15 Thread Roberto C . Sánchez
Hi Lars, I was preparing to package the 5.5.52 relese of MySQL for Debian Wheezy as part of my LTS work. However, I saw that you imported the new upstream release into the pkg-mysql/mysql-5.5 repository yesterday and made a debian/changelog to that effect. Do you intend to build and upload the p

Re: tiff / tiff3 / CVE-2015-7554 / CVE-2016-5318

2016-09-15 Thread Raphael Hertzog
On Thu, 15 Sep 2016, Brian May wrote: > What does the TIFFReadDirectoryFindFieldInfo function do? What > situations is TIFFReadDirectoryFindFieldInfo unsuccessful? I don't know. > You could perhaps mitigate by requiring an extra parameter that declares > the number of options you are parsing, how

Re: tiff / tiff3 / CVE-2015-7554 / CVE-2016-5318

2016-09-15 Thread Raphael Hertzog
On Thu, 15 Sep 2016, Brian May wrote: > Salvatore Bonaccorso writes: > > > Minor comment: if you are sure that those are duplicates you might try > > to contact MITRE to made them aware. > > I was just going based on what others have said, e.g. in the linked > reports. Would hope that one of the

Re: tiff / tiff3 / CVE-2015-7554 / CVE-2016-5318

2016-09-15 Thread Brian May
Raphael Hertzog writes: > I agree on all this but somehow I have the feeling that we can still > do better for example by blacklisting tags that are known to use a single > extension and refusing to handle them as custom > > My problem is that I'm not sure that we have a comprehensive list of suc

Re: tiff / tiff3 / CVE-2015-7554 / CVE-2016-5318

2016-09-15 Thread Brian May
Salvatore Bonaccorso writes: > Minor comment: if you are sure that those are duplicates you might try > to contact MITRE to made them aware. I was just going based on what others have said, e.g. in the linked reports. Would hope that one of them has already contacted MITRE... -- Brian May