Re: Bug#851612: CVE-2017-0381

2017-02-06 Thread Ron
On Mon, Feb 06, 2017 at 08:45:01PM +0100, Julien Cristau wrote: > On Tue, Jan 31, 2017 at 15:32:13 +1030, Ron wrote: > > > I've CC'd -release, to see what they'd prefer we do for Jessie. > > It might be that the best option here is to just put something later > > in -bpo, and if people are paranoi

Re: Bug#851612: CVE-2017-0381

2017-02-06 Thread Jean-Marc Valin
On 06/02/17 02:45 PM, Julien Cristau wrote: > On Tue, Jan 31, 2017 at 15:32:13 +1030, Ron wrote: > >> I've CC'd -release, to see what they'd prefer we do for Jessie. >> It might be that the best option here is to just put something later >> in -bpo, and if people are paranoid, they can choose to u

Re: Bug#851612: CVE-2017-0381

2017-02-06 Thread Julien Cristau
On Tue, Jan 31, 2017 at 15:32:13 +1030, Ron wrote: > I've CC'd -release, to see what they'd prefer we do for Jessie. > It might be that the best option here is to just put something later > in -bpo, and if people are paranoid, they can choose to use that? > I'd prefer to review patches rather tha

Re: Bug#851612: CVE-2017-0381

2017-01-30 Thread Ron
On Sun, Jan 29, 2017 at 04:39:59PM +0100, Salvatore Bonaccorso wrote: > On Tue, Jan 17, 2017 at 01:25:27AM -0500, Jean-Marc Valin wrote: > > Hi, > > > > CVE-2017-0381 states that: > > "A remote code execution vulnerability in silk/NLSF_stabilize.c in > > libopus in Mediaserver could enable an atta