Bug#998419: kodi: CVE-2021-42917

2021-11-04 Thread Vasyl Gello
Source: kodi Followup-For: Bug #998419 X-Debbugs-Cc: car...@debian.org Hi Salvatore! I have prepared the 2:19.1+dfsg2-3~deb11u1 upload in Salsa: https://salsa.debian.org/multimedia-team/kodi-media-center/kodi/-/tree/bullseye fixing the CVE for bullseye-pu with the debdiff attached. Vasyl --

Bug#998419: kodi: CVE-2021-42917

2021-11-04 Thread Vasyl Gello
Hi Salvatore! >> This bug was fixed in 19.3 upstream, and the sid/bookworm version is not >> vulnerable. > >Yes you are right, that was an error on my side, checking the source, >upstream commit and where the fix was included, thanks for correcting, >and apologies for the bad tracking at first.

Bug#998419: kodi: CVE-2021-42917

2021-11-03 Thread Salvatore Bonaccorso
Hi Vasyl, On Wed, Nov 03, 2021 at 10:05:01PM +, Vasyl Gello wrote: > Control: fixed -1 2:19.3+dfsg1-1 > Control: found -1 2:19.1+dfsg2-2~bpo10+1-1 > > Hi Salvatore! > > This bug was fixed in 19.3 upstream, and the sid/bookworm version is not > vulnerable. Yes you are right, that was an err

Bug#998419: kodi: CVE-2021-42917

2021-11-03 Thread Vasyl Gello
Control: notfound -1 2:19.3+dfsg1-1 --  Vasyl Gello == Certified SolidWorks Expert Mob.:+380 (98) 465 66 77 E-Mail: vasek.ge...@gmail.com Skype: vasek.gello == 호랑이는 죽어서 가죽을 남기고 사람은 죽어서 이름을 남긴다

Processed: Re: Bug#998419: kodi: CVE-2021-42917

2021-11-03 Thread Debian Bug Tracking System
Processing control commands: > notfound -1 2:19.3+dfsg1-1 Bug #998419 [src:kodi] kodi: CVE-2021-42917 No longer marked as found in versions kodi/2:19.3+dfsg1-1. -- 998419: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=998419 Debian Bug Tracking System Contact ow...@bugs.debian.org with probl

Bug#998419: kodi: CVE-2021-42917

2021-11-03 Thread Vasyl Gello
Control: found -1 2:17.1+dfsg1-3 Hi Salvatore, And what should I do with stretch & buster? Patch is applicable to everything since 10.x: https://github.com/xbmc/xbmc/commit/45285e8a9300cd754a760560640b75b09f98035e --  Vasyl Gello == Certified Soli

Processed: Re: Bug#998419: kodi: CVE-2021-42917

2021-11-03 Thread Debian Bug Tracking System
Processing control commands: > found -1 2:17.1+dfsg1-3 Bug #998419 [src:kodi] kodi: CVE-2021-42917 Marked as found in versions kodi/2:17.1+dfsg1-3. -- 998419: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=998419 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Processed: Re: Bug#998419: kodi: CVE-2021-42917

2021-11-03 Thread Debian Bug Tracking System
Processing control commands: > fixed -1 2:19.3+dfsg1-1 Bug #998419 [src:kodi] kodi: CVE-2021-42917 Ignoring request to alter fixed versions of bug #998419 to the same values previously set > found -1 2:19.1+dfsg2-2~bpo10+1-1 Bug #998419 [src:kodi] kodi: CVE-2021-42917 The source 'kodi' and versio

Processed: Re: Bug#998419: kodi: CVE-2021-42917

2021-11-03 Thread Debian Bug Tracking System
Processing control commands: > fixed -1 2:19.3+dfsg1-1 Bug #998419 [src:kodi] kodi: CVE-2021-42917 Marked as fixed in versions kodi/2:19.3+dfsg1-1. > found -1 2:19.1+dfsg2-2~bpo10+1-1 Bug #998419 [src:kodi] kodi: CVE-2021-42917 The source 'kodi' and version '2:19.1+dfsg2-2~bpo10+1-1' do not appear

Bug#998419: kodi: CVE-2021-42917

2021-11-03 Thread Vasyl Gello
Control: fixed -1 2:19.3+dfsg1-1 Control: found -1 2:19.1+dfsg2-2~bpo10+1-1 Hi Salvatore! This bug was fixed in 19.3 upstream, and the sid/bookworm version is not vulnerable. I would like to upload 19.3 to stable-pu or stable-sec but the approval from SRM is pending for 19.2. Is it possible to

Bug#998419: kodi: CVE-2021-42917

2021-11-03 Thread Salvatore Bonaccorso
Source: kodi Version: 2:19.3+dfsg1-1 Severity: important Tags: security upstream Forwarded: https://github.com/xbmc/xbmc/issues/20305 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for kodi. CVE-2021-42917[0]: | Buffer overflow vulnerability