Re: bluez / CVE-2020-0556

Roberto C. Sánchez <roberto@debian.org> writes:

> My own conclusion is that a backport of the stretch version of bluez is
> the best course.  If no objections are raised, then I will proceed with
> uploading the backport at the end of this week.

Sounds reasonable to me.

> I too concluded that something like this would be the closest adaptation
> of the upstream fix to the older bluez in jessie.  That said, I will
> note that the absence of enclosing braces around the two statements in
> your 'if' block make the 'return' fall outside the 'if'; the function
> will always return early here.

Oops. Probably obvious I mostly program in Python...
Brian May <bam@debian.org>

