Bug#851771: CVE-2016-6175 and 851771

2019-03-12 Thread Ivo De Decker
control: tags -1 buster-ignore Hi, On Sun, Jan 22, 2017 at 10:47:32PM +0100, Ola Lundqvist wrote: > I started checking the CVEs for php-gettext and I'm not sure I follow > the information for CVE-2016-6175. > Maybe you have more data than I do. > > The vulnerability is that a malicous user that

Bug#851771: CVE-2016-6175 and 851771

2017-01-22 Thread Ola Lundqvist
Hi Salvatore I started checking the CVEs for php-gettext and I'm not sure I follow the information for CVE-2016-6175. Maybe you have more data than I do. The vulnerability is that a malicous user that have permission to craft .mo files in the target filesystem could execute any php code on that s