Re: smb4k CVE-2017-8849

2017-08-14 Thread Markus Koschany
Hi, Am 12.08.2017 um 22:40 schrieb Moritz Mühlenhoff: > On Wed, Jun 21, 2017 at 06:54:57PM +0200, Markus Koschany wrote: >> Am 15.06.2017 um 18:49 schrieb Markus Koschany: >> [...] >>> Then I suggest we backport the Stretch version of smb4k to Wheezy and >>> Jessie. I have done this a few minutes

Re: smb4k CVE-2017-8849

2017-08-12 Thread Moritz Mühlenhoff
On Wed, Jun 21, 2017 at 06:54:57PM +0200, Markus Koschany wrote: > Am 15.06.2017 um 18:49 schrieb Markus Koschany: > [...] > > Then I suggest we backport the Stretch version of smb4k to Wheezy and > > Jessie. I have done this a few minutes ago for Wheezy and it was quite > > painless. It pulls in a

Re: smb4k CVE-2017-8849

2017-06-21 Thread Markus Koschany
Am 15.06.2017 um 18:49 schrieb Markus Koschany: [...] > Then I suggest we backport the Stretch version of smb4k to Wheezy and > Jessie. I have done this a few minutes ago for Wheezy and it was quite > painless. It pulls in a new dependency, libqt4-test, but apart from > that, mounting and unmountin

Re: smb4k CVE-2017-8849

2017-06-15 Thread Markus Koschany
Hi Salvatore, Am 15.06.2017 um 05:53 schrieb Salvatore Bonaccorso: [...] > As confirmed by upstream (for the jessie-Version): > > cut-cut-cut-cut-cut-cut- > proc.setProgram( args["command"].toStringList() ); > > // Run the mount process. > pr

Re: smb4k CVE-2017-8849

2017-06-14 Thread Salvatore Bonaccorso
Hi Maximiliano and Markus, On Wed, Jun 14, 2017 at 12:51:04PM +0200, Maximiliano Curia wrote: > ¡Hola Salvatore! > > El 2017-06-13 a las 13:47 +0200, Salvatore Bonaccorso escribió: > > Thanks for analyzing the code for older versions. > > > On Mon, Jun 12, 2017 at 11:52:00PM +0200, Markus Koscha

Re: smb4k CVE-2017-8849

2017-06-14 Thread Maximiliano Curia
¡Hola Salvatore! El 2017-06-13 a las 13:47 +0200, Salvatore Bonaccorso escribió: Thanks for analyzing the code for older versions. On Mon, Jun 12, 2017 at 11:52:00PM +0200, Markus Koschany wrote: I had a look at smb4k and CVE-2017-8849 and wanted to mark the package in Wheezy and Jessie as n

Re: smb4k CVE-2017-8849

2017-06-13 Thread Salvatore Bonaccorso
Hi Markus, Thanks for analyzing the code for older versions. On Mon, Jun 12, 2017 at 11:52:00PM +0200, Markus Koschany wrote: > Hi, > > I had a look at smb4k and CVE-2017-8849 and wanted to mark the package > in Wheezy and Jessie as not-affected. However I'm not completely sure > and I would lik

smb4k CVE-2017-8849

2017-06-12 Thread Markus Koschany
Hi, I had a look at smb4k and CVE-2017-8849 and wanted to mark the package in Wheezy and Jessie as not-affected. However I'm not completely sure and I would like to hear more opinions before I do it. According to the report on oss-security [1] it is possible for users to provide custom arguments