Re: Fixing CVE-2017-5617 (SSRF) for svgsalamander in wheezy

2017-02-03 Thread Sebastiaan Couwenberg
On 02/03/2017 11:06 AM, Guido Günther wrote: > On Fri, Feb 03, 2017 at 10:07:55AM +0100, Sebastiaan Couwenberg wrote: >> Dear LTS Team, >> >> Vincent Privat of the JOSM development team have provided a fix for >> CVE-2017-5617 (#853134). >> >> I've included a patch with his changes in the Debian pa

Re: Fixing CVE-2017-5617 (SSRF) for svgsalamander in wheezy

2017-02-03 Thread Guido Günther
On Fri, Feb 03, 2017 at 10:07:55AM +0100, Sebastiaan Couwenberg wrote: > Dear LTS Team, > > Vincent Privat of the JOSM development team have provided a fix for > CVE-2017-5617 (#853134). > > I've included a patch with his changes in the Debian package, and > uploaded it to unstable, and backporte

Fixing CVE-2017-5617 (SSRF) for svgsalamander in wheezy

2017-02-03 Thread Sebastiaan Couwenberg
Dear LTS Team, Vincent Privat of the JOSM development team have provided a fix for CVE-2017-5617 (#853134). I've included a patch with his changes in the Debian package, and uploaded it to unstable, and backported the patch for the jessie & wheezy packages. Affected versions: * jessie: 0~svn95