[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Fixes for CVE-2020-13696 (#962221)



Hi Mattia!

By partial I understood that upstream fixed the core part but the Debian patch sjould have been adapted to reflect new changes.
Jeremy, can you please correct me if I am wrong?
-- 
Vasyl Gello
Certified SolidWorks Expert

Mob.:+380 (98) 465 66 77

E-Mail: vasek.gello@gmail.com

Skype: vasek.gello
호랑이는 죽어서 가죽을 남기고 사람은 죽어서 이름을 남긴다

July 6, 2020 6:58:05 PM UTC, Mattia Rizzolo <mattia@debian.org> написав(-ла):
On Mon, Jul 06, 2020 at 05:10:30AM +0000, Vasyl Gello wrote:
Thanks for contributing the security release! I checked your changes and pushed them to the team repo.
I do not have an upload rights, so CCing Sebastian and Mattia.

Sure,

but could either of you do a bunch of housekeeping work as well, like:
* bumping dh compat
* drop --dbgsym-migration
* drop the .menu files
* would be awesome to have the copyright file rewrote using dep-5
* ....

Also, the commit adding the CVE patch mentions "partial fix", as does
the sec-tracker page. Can anybody explain shortly what's with that,
where is the full fix (if there is), and how come the LTS upload claims
this to be fully fixed instead (CCing the LTS team and the uploader for
this).

Attachment: signature.asc
Description: PGP signature


Reply to: