Re: addressing CVE-2018-1311/XERCESC-2188

2020-01-29 Thread Ola Lundqvist
Hi I have some questions below. I think your approach looks sensible but I'm not sure I have understood the description correctly. See below. On Fri, 24 Jan 2020 at 17:37, Hugo Lefeuvre wrote: > [c-dev senders: please CC me, I did not subscribe to the mailing list] > > Hi, > > I had a look at

Re: RFC: rmadison query in review-update-needed script

2020-01-29 Thread Ola Lundqvist
Hi The functionality looks useful. Should it even be part of lts-cve-triage.py script, or should it be a separate thing? I'm asking since I typically use just the lts-cve-triage.py script when working as front desk. If we should use several scripts maybe we should have a wrapper script around it t

Re: [CVE-2019-17026] Firefox Security Advisory 2020-03

2020-01-29 Thread Ben Hutchings
On Sun, 2020-01-26 at 16:17 +0100, Hugo Lefeuvre wrote: > Hi, > > > It seems urgent to me to correct a flaw exploited in firefox: > > https://www.mozilla.org/en-US/security/advisories/mfsa2020-03/ > > > > Here are the changes: > > https://raw.githubusercontent.com/HacKurx/public-sharing/master/fi