[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [Secure-testing-team] CVE-2007-1253: blender: eval injection vulnerability in kmz_ImportWithMesh.py



Florian Ernst wrote:
> On Tue, Mar 27, 2007 at 09:50:16PM +0200, Moritz Muehlenhoff wrote:
>> Florian Ernst wrote:
>>
>>>> Can you make an etch upload with only the removal of the buggy script?
>>>                   ^^^^
>>> Just for clarity's sake, you mean uploading to testing-proposed-updates?
>> Yes.
>>
>>> And it will get accepted?
>> The change in question would warrant a DSA, so I'm quite sure it will
>> get accepted if it only contains the change below. It's easily reviewable
>> and fixes a genuine security problem.
> 
> Very well, so here we go. :)
> 
> RMs, please accept blender_2.42a-5etch1. Debdiffs attached.

It will be approved if the mips and sparc builds get built and uploaded in time...

Cheers

Luk

-- 
Luk Claes - http://people.debian.org/~luk - GPG key 1024D/9B7C328D
Fingerprint:   D5AF 25FB 316B 53BB 08E7   F999 E544 DE07 9B7C 328D

Attachment: signature.asc
Description: OpenPGP digital signature


Reply to: