jquery / CVE-2019-11358

2019-05-01 Thread Brian May
The patch seems simple enough (see attached). Unfortunately, the minimisation that happens during build is just a little bit too efficient for my likes. Sure, 1 byte output is very efficient. dh_auto_build make[1]: Entering directory '/<>/jquery-1.7.2+dfsg' Building ./dist/jquery.js Minifying jQu

Re: CVE-2019-11627: Shell injection vulnerability in signing-party 1.1.10-3

2019-05-01 Thread Guilhem Moulin
On Wed, 01 May 2019 at 18:44:39 +0200, Markus Koschany wrote: > Thank you very much. I didn't want to bother you and went ahead and > uploaded your patch only an hour ago. I will issue the DLA now. Aha, should have refreshed the page before sending this :-P Thanks! -- Guilhem. signature.asc D

Re: CVE-2019-11627: Shell injection vulnerability in signing-party 1.1.10-3

2019-05-01 Thread Markus Koschany
Hi, Am 01.05.19 um 18:12 schrieb Guilhem Moulin: > Dear LTS team, > > CVE-2019-11627 was recently published for signing-party's gpg-key2ps(1): > > Unsafe shell call enabling shell injection via a User ID. > > See also #928256. gpg-key2ps(1) is a standalone CLI tool to generate a > PostScri

CVE-2019-11627: Shell injection vulnerability in signing-party 1.1.10-3

2019-05-01 Thread Guilhem Moulin
Dear LTS team, CVE-2019-11627 was recently published for signing-party's gpg-key2ps(1): Unsafe shell call enabling shell injection via a User ID. See also #928256. gpg-key2ps(1) is a standalone CLI tool to generate a PostScript file with OpenPGP key fingerprint slips. Note that the Securit