libvorbis request for comments

2018-04-19 Thread Antoine Beaupré
Hi, I have taken a look at the libvorbis issues pending in wheezy (and accidentally in jessie) and backported a few patches. The result is here, as usual, for testing: https://people.debian.org/~anarcat/debian/wheezy-lts/ Guido: you a lot of work on those issues with upstream, so it would be gre

april report

2018-04-19 Thread Antoine Beaupré
Hi, An early report as I've run out of hours sooner than expected... * frontdesk: one week of triage and a discussion about postponed packages and calibre maintenance and review. i also reviewed the ruby work later on and looked at the Firebird package * qemu: triaged out CVE-2018-78

Re: ruby1.9.1 test packages for wheezy

2018-04-19 Thread Gabriel Filion
Hi there, I've run a test on our setup here after getting a poke from Antoine. I'm not sure that the test is actually conclusive of anything though.. basically, it still works for us but that's probably because of how things are setup. we run the puppet master with passenger plus we've had some

Re: tiff: CVE-2018-8905: heap-based buffer overflow in LZWDecodeCompat

2018-04-19 Thread Hugo Lefeuvre
Hi, My current understanding of the problem (based on investigations on latest master, but also valid for older versions): The code_t string type is defined as a kind of chained list. Each entry contains: . a pointer to the next string entry . a length field indicating the remaining length of th