Re: addressing CVE-2018-1311/XERCESC-2188

2020-01-30 Thread Hugo Lefeuvre
Hi Ola, > > A DTDEntityDecl object is allocated and pushed into the ReaderMgr stack. > > ReaderMgr does not own the stack's content, so objects neither get freed on > > ReaderMgr::popReader(), nor on ReaderMgr::~ReaderMgr(). > > And it should not be freed by the code popping the object? I don't

Re: addressing CVE-2018-1311/XERCESC-2188

2020-01-30 Thread Ola Lundqvist
Hi Yes you answered my questions. Please go ahead to prepare a patch. / Ola Den tors 30 jan. 2020 09:09Hugo Lefeuvre skrev: > Hi Ola, > > > > A DTDEntityDecl object is allocated and pushed into the ReaderMgr > stack. > > > ReaderMgr does not own the stack's content, so objects neither get > fr

Re: on updating debian-security-support in stable and oldstable (due to DSA-4562-1)

2020-01-30 Thread Holger Levsen
hi, reviving this old issue (chromium is not supported anymore on stretch) On Thu, Nov 28, 2019 at 03:17:53PM +0100, Moritz Muehlenhoff wrote: > On Thu, Nov 28, 2019 at 12:03:25PM +, Holger Levsen wrote: > > - for stretch, I will upload to stretch-security and that's it. > Sounds good, I'll t

Re: on updating debian-security-support in stable and oldstable (due to DSA-4562-1)

2020-01-30 Thread Holger Levsen
On Thu, Jan 30, 2020 at 07:41:32PM +, Holger Levsen wrote: > I'll upload 2019.12.12~deb9u2 then which is lower than what's in > buster-pu currently and will be in buster soon. (2019.12.12~deb10u1) uploaded now. (once this is accepted I'll upload to jessie-security and be done.) -- cheers,

Re: RFC: rmadison query in review-update-needed script

2020-01-30 Thread Roberto C . Sánchez
On Wed, Jan 29, 2020 at 10:57:13PM +0100, Ola Lundqvist wrote: >Hi >The functionality looks useful. Should it even be part of >lts-cve-triage.py script, or should it be a separate thing? I'm asking >since I typically use just the lts-cve-triage.py script when working as >front d

Re: Unable to announce the updates

2020-01-30 Thread Utkarsh Gupta
Hi Emilio, On 13/01/20 10:11 am, Emilio Pozuelo Monfort wrote: > Using enigmail with PGP/mime has problems with debian lists for some reason. > So > that's most likely the cause. Just use inline PGP signatures when sending > mails > to -announce lists and you should be good. That worked! Many t

Re: [CVE-2019-17026] Firefox Security Advisory 2020-03

2020-01-30 Thread Ola Lundqvist
Hi I have added firefox-esr to dla-needed.txt file now. // Ola On Thu, 30 Jan 2020 at 01:06, Ben Hutchings wrote: > On Sun, 2020-01-26 at 16:17 +0100, Hugo Lefeuvre wrote: > > Hi, > > > > > It seems urgent to me to correct a flaw exploited in firefox: > > > https://www.mozilla.org/en-US/securi