March Report

2018-03-22 Thread Hugo Lefeuvre
Hi, March 2018 was my 19th month as a payed Debian LTS contributor. I was allocated 39.75 hours. I have spent 35.5h of them in the following tasks: * Continue my Ming work: - Finish to prepare patches for CVE-2018-5251, CVE-2018-5294, CVE-2018-6315 and CVE-2018-6359, prepare, test and u

Re: fixing CVE-2018-1050 in samba 3.3.6

2018-03-22 Thread Mathieu Parent
2018-03-21 23:01 GMT+01:00 Holger Levsen : > Dear samba maintainers, Hello, > the fix for CVE-2018-1050 (eg from 4.5.12+dfsg-2+deb9u) applies cleanly > on 3.6.6-6+deb7u15, however CVE-2018-1050 says that only versions >4.0.0 > are affected. > > Since (afaics) there is no known exploit I cannot re

Re: [Pkg-samba-maint] fixing CVE-2018-1050 in samba 3.3.6

2018-03-22 Thread Andrew Bartlett
On Wed, 2018-03-21 at 22:01 +, Holger Levsen wrote: > Dear samba maintainers, > > the fix for CVE-2018-1050 (eg from 4.5.12+dfsg-2+deb9u) applies cleanly > on 3.6.6-6+deb7u15, however CVE-2018-1050 says that only versions >4.0.0 > are affected. > > Since (afaics) there is no known exploit I c