Python3.4 / CVE-2016-5636

2019-01-12 Thread Brian May
Supposedly this should be the patch for the problem: https://hg.python.org/cpython/rev/fa006d671f41 However all I seem to be able to find is an empty patch. Although the files listed is correct. Can anyone here see how to find the correct patch? There is a good patch here: https://hg.python.or

Re: Assistance with building symfony for jessie

2019-01-12 Thread Abhijith PA
Hi Roberto On Sunday 13 January 2019 06:26 AM, Roberto C. Sánchez wrote: > Hello all, > > I have been working on the LTS update for symfony and while I completed > the backports of all of the patches several weeks ago I have not managed > to get the package to build on jessie. In particular, the

Assistance with building symfony for jessie

2019-01-12 Thread Roberto C . Sánchez
Hello all, I have been working on the LTS update for symfony and while I completed the backports of all of the patches several weeks ago I have not managed to get the package to build on jessie. In particular, the build fails because of the unit tests. To determine if any of my changes had anyth

qemu - CVE-2018-19665: bt subsystem mishandles negative length variables

2019-01-12 Thread Hugo Lefeuvre
Hi, I had a look at CVE-2018-19665 regarding qemu in oldstable/stable. summary: the bluetooth subsystem uses signed length variables at multiple places. These length variables are used, among others, in memcpy calls. A malicious guest VM could attempt to crash the host by passing negative len val