Re: Call for advice regarding curl CVE-2016-9586

2016-12-25 Thread Guido Günther
Hi Ola, On Fri, Dec 23, 2016 at 11:54:11PM +0100, Ola Lundqvist wrote: > Hi > > I have looked into CVE-2016-9586 affecting curl. > What I'm trying to figure out is whether it is worth the effort to fix > it or not. > > More info here: > https://curl.haxx.se/docs/adv_20161221A.html > > 1) There a

Re: unrealize mechanism in 9pfs

2016-12-25 Thread Hugo Lefeuvre
Hi Guido, Thank you for your investigations. I've marked CVE-2016-9914/15/16 as no-dsa and will upload my patches for the two remaining issues. Cheers, Hugo -- Hugo Lefeuvre (hle)|www.owl.eu.com 4096/ ACB7 B67F 197F 9B32 1533 431C AC90 AC3E C524 065E signature.asc Descr

Wheezy update of curl?

2016-12-25 Thread Ola Lundqvist
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of curl: https://security-tracker.debian.org/tracker/CVE-2016-9586 Would you like to take care of this yourself? If yes, please follow the workflow we have defined h