Re: CVE triage in the tracker

2018-05-17 Thread Salvatore Bonaccorso
Hi On Tue, May 15, 2018 at 07:34:31PM -0400, Hugo Lefeuvre wrote: > > > > Then you can put: > > > > > > > > - ming > > > > > > It's already the case. That's why I asked. ;) > > > > The "(unstable) - (unfixed)" for removed packages is actually a glitch in > > the tracker. > > > > Patc

Re: CVE triage in the tracker

2018-05-15 Thread Hugo Lefeuvre
> > > Then you can put: > > > > > > - ming > > > > It's already the case. That's why I asked. ;) > > The "(unstable) - (unfixed)" for removed packages is actually a glitch in the > tracker. > > Patches welcome :-) I'll take a look at it then. Thanks ! Cheers, Hugo -- Hugo

Re: CVE triage in the tracker

2018-05-15 Thread Moritz Muehlenhoff
Hugo Lefeuvre wrote: I added a few more ming CVEs earlier the day, BTW. > > > Second question: Even if Ming isn't present in unstable, the tracker > > > still mentions (unstable) - (unfixed) in the second table. IMO this > > > row makes no sense, is it a bug ? > > > > Then you can put: > > > >

Re: CVE triage in the tracker

2018-05-15 Thread Hugo Lefeuvre
Hi, > > [wheezy] - ming 0.4.4-1.1+deb7u8 > > > > Still I'm not completely sure it's the right way to proceed. Can anybody > > take a look ? > > Yes, if the vulnerability was fixed, even in a previous version, better add > the exact version. Thanks ! > > Second question: Even if Ming isn't pres

Re: CVE triage in the tracker

2018-05-15 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, 2018-05-15 at 00:14 -0400, Hugo Lefeuvre wrote: > but I'm pretty sure it was wrong, so I changed[0] it to > > [wheezy] - ming 0.4.4-1.1+deb7u8 > > Still I'm not completely sure it's the right way to proceed. Can anybody > take a look ? Yes

CVE triage in the tracker

2018-05-14 Thread Hugo Lefeuvre
Hi, I've had a look at Ming CVEs these last days, and a lot of them were already fixed in Wheezy since 1:0.4.4-1.1+deb7u8, where I fixed a lot of potential weaknesses. However I'm not completely sure about how to fill these information in the tracker. At first I did [wheezy] - ming (Already fix