Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Incomplete patch for CVE-2020-10936? #947

Closed
utkarsh2102 opened this issue May 25, 2020 · 4 comments
Closed

Incomplete patch for CVE-2020-10936? #947

utkarsh2102 opened this issue May 25, 2020 · 4 comments
Labels

Comments

@utkarsh2102
Copy link

Hi @ikedas,

Thanks for the fix for CVE-2020-10936 :)
The announcement claims that the relevant patch for this is this commit: 3f8449c

However, it seems that there are claims of incompleteness at: #943 (comment)

Whilst I'd want to fix this in Debian, I'd want to know if this indeed is incomplete or not? Is there any left out bit other than the forementioned commit (3f8449c)?
Does this need any more patching than this?

It'd be really helpful if you could possibly help with this. Once done, I'll proceed with this fix in Debian.

@racke
Copy link
Contributor

racke commented May 25, 2020

The patch mentioned in #943 was sent 2018 to the Sympa security list and was not disclosed to the public. I think it would be possible to send it to the Debian security team for further consideration.

@utkarsh2102
Copy link
Author

utkarsh2102 commented May 25, 2020

It'd be great if this could be done.
Please consider reaching the Security team at: team[at]security[dot]debian[dot]org
I'd really appreciate if you could CC me in this thread: utkarsh[at]debian[dot]org

Thanks in advance :)

@racke
Copy link
Contributor

racke commented May 26, 2020

Done. You are welcome @utkarsh2102

@ikedas
Copy link
Member

ikedas commented Jun 23, 2020

There doesn't seem the evidence that our patch for CVE-2020-10936 is incomplete.

This issue is closed for now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants