Bug#594393: CVE-2010-2947

2010-08-25 Thread Bastian Kleineidam
Hi, I prepared an update for libhx 1.18 in stable and sent it to the security team for review. After they give me the go libhx 1.18 in stable will be updated with the security fix. Regards, Bastian Am Mittwoch, 25. August 2010, 23:49:55 schrieb Jan Engelhardt: > >Please check whether stable

Bug#594393: CVE-2010-2947

2010-08-25 Thread Jan Engelhardt
>Please check whether stable is affected. As the commit log says: Affects all versions prior to, and including, 3.5. So yes, stable is affected (unless somebody was already quick to fix it there). -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of

Bug#594393: CVE-2010-2947

2010-08-25 Thread Moritz Muehlenhoff
Package: libhx Severity: grave Tags: security The following was posted to oss-security and has been assigned CVE-2010-2947: --- http://libhx.git.sourceforge.net/git/gitweb.cgi?p=libhx/libhx;a=commitdiff;h=904a46f90dd3f046bfac0b64a5e813d7cd4fca59 string: fixed buffer overflow in HX_split when too