Re: tiff: CVE-2018-8905: heap-based buffer overflow in LZWDecodeCompat

2018-04-22 Thread Hugo Lefeuvre
It looks like this buffer overflow is the consequence of an earlier buffer overflow in the GetNextCodeCompat macro: > #define GetNextCodeCompat(sp, bp, code) { \ > nextdata |= (unsigned long) *(bp)++ << nextbits;\ > nextbits += 8;

Re: ruby1.9.1 test packages for wheezy

2018-04-22 Thread Santiago R.R.
El 19/04/18 a las 18:07, Gabriel Filion escribió: > Hi there, > > I've run a test on our setup here after getting a poke from Antoine. > > I'm not sure that the test is actually conclusive of anything though.. > basically, it still works for us but that's probably because of how > things are setu

linux backport in jessie LTS

2018-04-22 Thread Ben Hutchings
The backports team decided in 2016 that backports suites will no longer be updated once the corresponding stable suite enters LTS. This implies that jessie-backports will be closed at the end of May. It is clear that a fair number of wheezy LTS users relied on backported kernel versions and were