Re: Fixes for CVE-2020-13696 (#962221)

2020-07-08 Thread Mattia Rizzolo
On Wed, Jul 08, 2020 at 09:07:25AM +0100, Jeremy Sowden wrote: ... > The new upstream release added extra checks to ensure that the object at > the end of the path is a device file of the right sort before opening > it: ... > However, the error messages still leak information, allowing the user to

Re: Fixes for CVE-2020-13696 (#962221)

2020-07-08 Thread Jeremy Sowden
On 2020-07-06, at 19:11:09 +, Vasyl Gello wrote: > July 6, 2020 6:58:05 PM UTC, Mattia Rizzolo написав(-ла): > > On Mon, Jul 06, 2020 at 05:10:30AM +, Vasyl Gello wrote: > > > Thanks for contributing the security release! I checked your > > > changes and pushed them to the team repo. I do

Re: Fixes for CVE-2020-13696 (#962221)

2020-07-06 Thread Vasyl Gello
Hi Mattia! By partial I understood that upstream fixed the core part but the Debian patch sjould have been adapted to reflect new changes. Jeremy, can you please correct me if I am wrong? --  Vasyl Gello == Certified SolidWorks Expert Mob.:+380 (98

Re: Fixes for CVE-2020-13696 (#962221)

2020-07-06 Thread Mattia Rizzolo
On Mon, Jul 06, 2020 at 05:10:30AM +, Vasyl Gello wrote: > Thanks for contributing the security release! I checked your changes and > pushed them to the team repo. > I do not have an upload rights, so CCing Sebastian and Mattia. Sure, but could either of you do a bunch of housekeeping work a