Bug#868185: CVE-2016-4383

2017-08-06 Thread Moritz Mühlenhoff
On Mon, Jul 24, 2017 at 12:44:21AM +0200, Thomas Goirand wrote: > Hi, > > Reading the comments at https://bugs.launchpad.net/glance/+bug/1593799/, > it looks like upstream : > - will never write a fix > - don't feel like it's a big problem > - only wrote an announcement > > Or just ignore the iss

Bug#868185: CVE-2016-4383

2017-07-23 Thread Thomas Goirand
Hi, Reading the comments at https://bugs.launchpad.net/glance/+bug/1593799/, it looks like upstream : - will never write a fix - don't feel like it's a big problem - only wrote an announcement Therefore, what's the recommended course of action for Debian? Should we also publish the upstream recom

Bug#868185: CVE-2016-4383

2017-07-12 Thread Moritz Muehlenhoff
Source: glance Severity: important Tags: security Hi, please see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4383 Cheers, Moritz