Re: Triage advice for CVE-2020-8492

2020-02-03 Thread Ola Lundqvist
Hi Reverted the decision that it is minor. Instead added python to dla needed. // Ola On Mon, 3 Feb 2020 at 11:30, Ola Lundqvist wrote: > Hi Ben > > Thank you. I realize that I misunderstood things. It is the server side > that sends this string, not the user on the client side. I'll adjust my

Re: spamassassin security update in Debian jessie LTS

2020-02-03 Thread Noah Meyerhans
On Sat, Feb 01, 2020 at 03:28:09PM +, Mike Gabriel wrote: > So, I'd like to play the ball back to Noah. Do you think, that applying the > security patches is sufficient for spamassassin in stretch/buster? Or have > their been so many other fixes(TM) that justify an upstream backport to > jessie

(semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2020-02-03 Thread Holger Levsen
hi, today I unclaimed for LTS: - opendmarc (Thorsten Alteholz) - openjdk-7 (Emilio) - python-pysaml2 (Abhijith PA) - ruby-rack-cors (Utkarsh Gupta) for eLTS: - openjdk-7 (Emilio) Then, the following DLAs are missing on www.debian.org: ERROR: .data or .wml file missing for DLA 2090-1 ERROR: .d

Re: Triage advice for CVE-2020-8492

2020-02-03 Thread Ola Lundqvist
Hi Ben Thank you. I realize that I misunderstood things. It is the server side that sends this string, not the user on the client side. I'll adjust my analysis accordingly. This means that a malicious server can cause a DoS on client side. Best regards // Ola On Sun, 2 Feb 2020 at 23:55, Ben Hu