Re: Patch proposal for CVE-2017-6960 in Wheezy (/Jessie)

2017-06-02 Thread Hugo Lefeuvre
Hi Ola, > I have reviewed your code and it looks good to me. I do not know this > library very well however so may have overlooked something. But the > checks looks ok. > > What I'm not sure of is the break statement, but I guess you have > control over that part. Thanks for your review ! This

Re: Patch proposal for CVE-2017-6960 in Wheezy (/Jessie)

2017-05-31 Thread Ola Lundqvist
Hi Hugo I have reviewed your code and it looks good to me. I do not know this library very well however so may have overlooked something. But the checks looks ok. What I'm not sure of is the break statement, but I guess you have control over that part. Have you tested that the solution work agai

Patch proposal for CVE-2017-6960 in Wheezy (/Jessie)

2017-05-25 Thread Hugo Lefeuvre
Hi, I have prepared a patch for apng2gif 1.5. Testing did not reveal any problem, but I'm sure it can still be improved. Could anybody take a look at it ? Debdiff for wheezy is in attachment (a test package for wheezy is also available here[0]). This patch should also fix the issue in Jessie,