[Bug 1737364] Re: 16.04: Fix CVE-2016-1968 and CVE-2016-1624 for brotli

2018-02-05 Thread Launchpad Bug Tracker
This bug was fixed in the package brotli - 0.3.0+dfsg-2ubuntu1 --- brotli (0.3.0+dfsg-2ubuntu1) xenial-security; urgency=medium * SECURITY UPDATE: integer underflow in dec/decode.c (LP: #1737364) - debian/patches/fix-integer-underflow.patch: upstream patch via Debian - CVE-2

[Bug 1737364] Re: 16.04: Fix CVE-2016-1968 and CVE-2016-1624 for brotli

2018-02-05 Thread Marc Deslauriers
ACK on the debdiff in comment #1. Package is building now and will be released as a security update. Thanks! ** Also affects: brotli (Ubuntu Xenial) Importance: Undecided Status: New ** Changed in: brotli (Ubuntu) Status: New => Fix Released ** Changed in: brotli (Ubuntu Xenial)

[Bug 1737364] Re: 16.04: Fix CVE-2016-1968 and CVE-2016-1624 for brotli

2017-12-09 Thread Jeremy Bicha
** Patch added: "brotli-xenial-lp1737364.debdiff" https://bugs.launchpad.net/ubuntu/+source/brotli/+bug/1737364/+attachment/5020748/+files/brotli-xenial-lp1737364.debdiff ** Tags added: patch ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2016-1624 ** CVE added: https://cve.mit