Re: CVE-2023-6918: removal of unused evp functions & types

2024-02-26 Thread Jakub Jelen
Hi, This CVE is about checking return code from the crypto library API calls, which could fail and cause some unexpected behavior such as usage of uninitialized memory, DoS, ... Our analysis did not show any important exploitable code path (but it was in supported libssh versions -- this might not

Re: CVE-2023-6918: removal of unused evp functions & types

2024-02-26 Thread Sean Whitton
Hello, On Mon 26 Feb 2024 at 09:38am +01, Jakub Jelen wrote: > This CVE is about checking return code from the crypto library API > calls, which could fail and cause some unexpected behavior such as > usage of uninitialized memory, DoS, ... Our analysis did not show any > important exploitable co

imagemagick LTS

2024-02-26 Thread Sean Whitton
Hello Bastien, Is there someway I could help with imagemagick under LTS? It looks like the status has been unchanged for some months. I'm not an expert but I can review things. Thanks! -- Sean Whitton

python-django LTS

2024-02-26 Thread Sean Whitton
Hello Chris, Do you have WIP for python-django LTS fixes? Can I work on it without duplicating effort? Thought I'd check, since you're the maintainer. -- Sean Whitton signature.asc Description: PGP signature