Re: buffer overflow vulnerability in netmask 2.3.12

2019-02-06 Thread Antoine Beaupré
On 2019-02-06 21:52:35, Guilhem Moulin wrote: > Hi anarcat, > > On Wed, 06 Feb 2019 at 14:13:23 -0500, Antoine Beaupré wrote: >> 4. issue a DLA when the package is accepted > > I wouldn't mind if you or another LTS team member were talking care of > this one :-) Alright, DLA coming right up! :) A

Re: buffer overflow vulnerability in netmask 2.3.12

2019-02-06 Thread Guilhem Moulin
Hi anarcat, On Wed, 06 Feb 2019 at 14:13:23 -0500, Antoine Beaupré wrote: > On 2019-02-06 01:59:58, Guilhem Moulin wrote: >> * Upstream hasn't yet filed a CVE for this issue; I forwarded jmm's >> instructions regarding this. > > Sorry, forwarded where? Did I miss something? Ah sorry, that's inde

Re: buffer overflow vulnerability in netmask 2.3.12

2019-02-06 Thread Antoine Beaupré
On 2019-02-06 01:59:58, Guilhem Moulin wrote: > Dear LTS team, Hi Guilhem! > A buffer overflow vulnerability was recently found in the netmask > package (a small utility that helps determining network masks): > > https://github.com/tlby/netmask/issues/3 > > The Security Team argued that the v

buffer overflow vulnerability in netmask 2.3.12

2019-02-05 Thread Guilhem Moulin
Dear LTS team, A buffer overflow vulnerability was recently found in the netmask package (a small utility that helps determining network masks): https://github.com/tlby/netmask/issues/3 The Security Team argued that the version in stretch (2.4.3-1) doesn't warrant a DSA as the program is bui