Bug#819499: wheezy-pu: package optipng/0.6.4-1

2016-04-08 Thread Adam D. Barratt
Control: tags -1 + pending On Tue, 2016-03-29 at 21:18 +0200, Markus Koschany wrote: > Am 29.03.2016 um 20:52 schrieb Adam D. Barratt: > > Control; tags -1 + confirmed > > > > On Tue, 2016-03-29 at 19:16 +0200, Markus Koschany wrote: > >> I have prepared a security update for optipng in wheezy to

Bug#819499: wheezy-pu: package optipng/0.6.4-1

2016-03-29 Thread Markus Koschany
Am 29.03.2016 um 20:52 schrieb Adam D. Barratt: > Control; tags -1 + confirmed > > On Tue, 2016-03-29 at 19:16 +0200, Markus Koschany wrote: >> I have prepared a security update for optipng in wheezy to address >> CVE-2015-7801. I have contacted the security team but they don't think >> this issue

Bug#819499: wheezy-pu: package optipng/0.6.4-1

2016-03-29 Thread Adam D. Barratt
Control; tags -1 + confirmed On Tue, 2016-03-29 at 19:16 +0200, Markus Koschany wrote: > I have prepared a security update for optipng in wheezy to address > CVE-2015-7801. I have contacted the security team but they don't think > this issue warrants a DSA. Please find attached the debdiff. Pleas

Bug#819499: wheezy-pu: package optipng/0.6.4-1

2016-03-29 Thread Markus Koschany
More information: The initial report for CVE-2015-7801 on seclists.org can be found at http://seclists.org/oss-sec/2015/q3/556 The reproducer can be downloaded from RedHat's bug tracker: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-7801 Markus signature.asc Description: OpenPGP digi

Bug#819499: wheezy-pu: package optipng/0.6.4-1

2016-03-29 Thread Markus Koschany
Package: release.debian.org Severity: normal Tags: wheezy User: release.debian@packages.debian.org Usertags: pu Hello, I have prepared a security update for optipng in wheezy to address CVE-2015-7801. I have contacted the security team but they don't think this issue warrants a DSA. Please fi