-
Notifications
You must be signed in to change notification settings - Fork 103
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Incomplete patch for CVE-2020-10936? #947
Comments
The patch mentioned in #943 was sent 2018 to the Sympa security list and was not disclosed to the public. I think it would be possible to send it to the Debian security team for further consideration. |
It'd be great if this could be done. Thanks in advance :) |
Done. You are welcome @utkarsh2102 |
There doesn't seem the evidence that our patch for CVE-2020-10936 is incomplete. This issue is closed for now. |
Hi @ikedas,
Thanks for the fix for CVE-2020-10936 :)
The announcement claims that the relevant patch for this is this commit: 3f8449c
However, it seems that there are claims of incompleteness at: #943 (comment)
Whilst I'd want to fix this in Debian, I'd want to know if this indeed is incomplete or not? Is there any left out bit other than the forementioned commit (3f8449c)?
Does this need any more patching than this?
It'd be really helpful if you could possibly help with this. Once done, I'll proceed with this fix in Debian.
The text was updated successfully, but these errors were encountered: