Re: libcdio stable update for CVE-2007-6613

2008-01-22 Thread Moritz Muehlenhoff
On 2008-01-21, Nicolas Boullis <[EMAIL PROTECTED]> wrote: > Hi Nico and others, > > On Sun, Jan 20, 2008 at 02:31:39PM +0100, Nico Golde wrote: >> Hi, >> the following CVE (Common Vulnerabilities & Exposures) id was >> published for libcdio some time ago. >> >> CVE-2007-6613[0]: >> | Stack-based b

Re: libcdio stable update for CVE-2007-6613

2008-01-21 Thread Nico Golde
Hi Nicolas, * Nicolas Boullis <[EMAIL PROTECTED]> [2008-01-22 00:40]: > On Sun, Jan 20, 2008 at 02:31:39PM +0100, Nico Golde wrote: [...] > > Unfortunately the vulnerability described above is not important enough > > to get it fixed via regular security update in Debian stable. It does > > not wa

Re: libcdio stable update for CVE-2007-6613

2008-01-21 Thread Nicolas Boullis
Hi Nico and others, On Sun, Jan 20, 2008 at 02:31:39PM +0100, Nico Golde wrote: > Hi, > the following CVE (Common Vulnerabilities & Exposures) id was > published for libcdio some time ago. > > CVE-2007-6613[0]: > | Stack-based buffer overflow in the print_iso9660_recurse function in > | iso-info