Processed: Re: Bug#760385: Fix for CVE-2014-5256

2014-12-19 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #760385 [libv8-3.14] nodejs: CVE-2014-5256 Severity set to 'important' from 'grave' -- 760385: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=760385 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To UNSUBSCRI

Bug#760385: Fix for CVE-2014-5256

2014-12-19 Thread Michael Gilbert
control: severity -1 important There is no security support for libv8 in jessie, so security issues aren't RC. Best wishes, Mike -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#760385: Fix for CVE-2014-5256

2014-11-15 Thread Jean Baptiste Favre
I meant "I'm *not* sure I'll be able to deal with lib8-3.14 Sorry, Jean Baptiste On 15/11/2014 21:28, Jean Baptiste Favre wrote: > Hello Thomas, > Thanks for your update. > > I decided to have a look on this bug because it seemed quite easy to fix > it: upstream patch was available and small ano

Bug#760385: Fix for CVE-2014-5256

2014-11-15 Thread Jean Baptiste Favre
Hello Thomas, Thanks for your update. I decided to have a look on this bug because it seemed quite easy to fix it: upstream patch was available and small anough for me. Unfortunatly, I'm sure I'll be able to deal with lib8-3.14. The more I dig into, the less I understand (more or less) :) I'll tr

Bug#760385: Fix for CVE-2014-5256

2014-11-15 Thread Thomas Viehmann
Hi Jean Baptiste, thank you for looking into this. Note that the changelog entries for nodejs 0.10.31 and .32 include v8: backport CVE-2013-6668 v8: fix a crash introduced by previous release If libv8 in Debian is affected by those, you might also consider also backporting those fixes when p