Bug#702346: icu: CVE-2013-0900

2013-03-18 Thread Julien Cristau
On Mon, Mar 18, 2013 at 18:55:40 +0100, Moritz Mühlenhoff wrote: > On Sat, Mar 16, 2013 at 01:49:24PM -0400, Jay Berkenbilt wrote: > > > They also send me links to the upstream fixes: > > > http://bugs.icu-project.org/trac/changeset/32865 > > > http://bugs.icu-project.org/trac/changeset/32908 > >

Bug#702346: icu: CVE-2013-0900

2013-03-18 Thread Moritz Mühlenhoff
On Sat, Mar 16, 2013 at 01:49:24PM -0400, Jay Berkenbilt wrote: > > They also send me links to the upstream fixes: > > http://bugs.icu-project.org/trac/changeset/32865 > > http://bugs.icu-project.org/trac/changeset/32908 > > I can prepare a new upload with these fixes and call it CVE-2013-0900. >

Bug#702346: icu: CVE-2013-0900

2013-03-16 Thread Jay Berkenbilt
Jay Berkenbilt wrote: >> They also send me links to the upstream fixes: >> http://bugs.icu-project.org/trac/changeset/32865 >> http://bugs.icu-project.org/trac/changeset/32908 > > I can prepare a new upload with these fixes and call it CVE-2013-0900. > There's a one-line fix for a Malayalam rende

Bug#702346: icu: CVE-2013-0900

2013-03-16 Thread Jay Berkenbilt
Moritz Muehlenhoff wrote: > Google fixed a security issue in icu, which is embedded in Chrome: > http://googlechromereleases.blogspot.de/2013/02/stable-channel-update_21.html > > | [152442] Medium CVE-2013-0900: Race condition in ICU. Credit to > Google Chrome Security Team (Inferno). > > I conta

Bug#702346: icu: CVE-2013-0900

2013-03-05 Thread Moritz Muehlenhoff
Package: icu Severity: grave Tags: security Justification: user security hole Hi Jay, Google fixed a security issue in icu, which is embedded in Chrome: http://googlechromereleases.blogspot.de/2013/02/stable-channel-update_21.html | [152442] Medium CVE-2013-0900: Race condition in ICU. Credit to