Re: Bug#866890: pspp - cve-2017-10791 - cve-2017-10792

2017-07-04 Thread Friedrich Beckmann
spect this report is mistaken. But this bit is Ben's code, so I'll let >> him comment on >> that. >> >> J' >> >> On Mon, Jul 03, 2017 at 07:22:57AM +0200, Friedrich Beckmann wrote: >> Dear owl337 team, >> >> thanks for

Re: Bug#866890: pspp - cve-2017-10791 - cve-2017-10792

2017-07-03 Thread Friedrich Beckmann
Hi John, > Am 04.07.2017 um 07:10 schrieb John Darrington : > > On Mon, Jul 03, 2017 at 11:37:30PM +0200, Friedrich Beckmann wrote: > Hi John, > > today I looked a little bit at the hash function. I think the problem is > that compared to > the referenced

Re: Bug#866890: pspp - cve-2017-10791 - cve-2017-10792

2017-07-03 Thread Friedrich Beckmann
4 Bit architectures. The reference only talks about uint32_t. Regards Friedrich > Am 03.07.2017 um 20:50 schrieb John Darrington : > > I suspect this report is mistaken. But this bit is Ben's code, so I'll let > him comment on > that. > > J' > > On M

Re: Wheezy update of pspp?

2017-07-03 Thread Friedrich Beckmann
Hi Thorsten, thanks for looking into this problem. According to the bug information this problem is present also in upstream. So I think we will look into this and once a fix is available we will contact you again how to put this eventually into older pspp versions. Regards Friedrich > Am 02.0

pspp - cve-2017-10791 - cve-2017-10792

2017-07-02 Thread Friedrich Beckmann
Dear owl337 team, thanks for looking at pspp and finding the security problems https://security-tracker.debian.org/tracker/CVE-2017-10791 and https://security-tracker.debian.org/tracker/CVE-2017-10792 in pspp! Your reports are quite detailed. Could you describe how you found the problems, i.e