Bug#951907: Suggested Stable Fix

2020-02-28 Thread Salvatore Bonaccorso
Hi Scott, On Fri, Feb 28, 2020 at 03:30:01PM -0500, Scott Kitterman wrote: > On Thursday, February 27, 2020 8:11:32 AM EST Salvatore Bonaccorso wrote: > > Hi Scott, > > > > On Thu, Feb 27, 2020 at 01:41:44PM +0100, Salvatore Bonaccorso wrote: > > > Hi, > > > > > > On Thu, Feb 27, 2020 at 01:18:5

Bug#951907: Suggested Stable Fix

2020-02-28 Thread Scott Kitterman
On Thursday, February 27, 2020 8:11:32 AM EST Salvatore Bonaccorso wrote: > Hi Scott, > > On Thu, Feb 27, 2020 at 01:41:44PM +0100, Salvatore Bonaccorso wrote: > > Hi, > > > > On Thu, Feb 27, 2020 at 01:18:55PM +0100, Salvatore Bonaccorso wrote: > > > I think though we mgiht need to revisit the a

Bug#951907: Suggested Stable Fix

2020-02-27 Thread Salvatore Bonaccorso
Hi Scott, On Thu, Feb 27, 2020 at 01:05:58PM +, Scott Kitterman wrote: [...] > ... > > I'll see if I can figure something out. In the older versions it's > all passed to html5lib in a glob of kw args. I'm not sure if that > means the problem in html5lib (bad defaults) or if there is a way t

Bug#951907: Suggested Stable Fix

2020-02-27 Thread Scott Kitterman
On February 27, 2020 12:18:53 PM UTC, Salvatore Bonaccorso wrote: >Hi Scott, > >On Thu, Feb 27, 2020 at 06:24:09AM -0500, Scott Kitterman wrote: >> On Thursday, February 27, 2020 2:44:48 AM EST Salvatore Bonaccorso >wrote: >> > Hi Scott, >> > >> > On Sat, Feb 22, 2020 at 07:20:34PM -0500, Sco

Bug#951907: Suggested Stable Fix

2020-02-27 Thread Salvatore Bonaccorso
Hi Scott, On Thu, Feb 27, 2020 at 01:41:44PM +0100, Salvatore Bonaccorso wrote: > Hi, > > On Thu, Feb 27, 2020 at 01:18:55PM +0100, Salvatore Bonaccorso wrote: > > I think though we mgiht need to revisit the assessment that older > > versions are not affected. Look at the this quick and dirty tes

Bug#951907: Suggested Stable Fix

2020-02-27 Thread Salvatore Bonaccorso
Hi, On Thu, Feb 27, 2020 at 01:18:55PM +0100, Salvatore Bonaccorso wrote: > I think though we mgiht need to revisit the assessment that older > versions are not affected. Look at the this quick and dirty test > deduced from the testsuite: So I think versions before are as well vulnerable but a fi

Bug#951907: Suggested Stable Fix

2020-02-27 Thread Salvatore Bonaccorso
Hi Scott, On Thu, Feb 27, 2020 at 06:24:09AM -0500, Scott Kitterman wrote: > On Thursday, February 27, 2020 2:44:48 AM EST Salvatore Bonaccorso wrote: > > Hi Scott, > > > > On Sat, Feb 22, 2020 at 07:20:34PM -0500, Scott Kitterman wrote: > > > Debdiff for proposed stable security update attached.

Bug#951907: Suggested Stable Fix

2020-02-27 Thread Scott Kitterman
On Thursday, February 27, 2020 2:44:48 AM EST Salvatore Bonaccorso wrote: > Hi Scott, > > On Sat, Feb 22, 2020 at 07:20:34PM -0500, Scott Kitterman wrote: > > Debdiff for proposed stable security update attached. > > > > The first hunk of the patch has the actual fix. I would prefer to use the >

Bug#951907: Suggested Stable Fix

2020-02-26 Thread Salvatore Bonaccorso
Hi Scott, On Sat, Feb 22, 2020 at 07:20:34PM -0500, Scott Kitterman wrote: > Debdiff for proposed stable security update attached. > > The first hunk of the patch has the actual fix. I would prefer to use the > new > ustream release rather than just patch the one line because of the test > im

Bug#951907: Suggested Stable Fix

2020-02-22 Thread Scott Kitterman
Debdiff for proposed stable security update attached. The first hunk of the patch has the actual fix. I would prefer to use the new ustream release rather than just patch the one line because of the test improvements, of the explanation of the issue in the upstream changeslog, and using the ne