Steve Kemp wrote: > > Please tell whether you deem those patches sufficient for a potential > > future security advisory, and if not, please provide pointers at what > > might be missing. > > It looks good to me.
I can confirm the patch for CVE-2005-3302 is correct, I've sent a similar patch a few weeks ago. > I've built a package and if nobody has any > objections I'll upload later today. Are you aware of CVE-2005-3151? Real-world exploitability seems quite unlikely, though. Cheers, Moritz -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]