Merge lp:~jtaylor/ubuntu/oneiric/dropbear/CVE-2012-0920 into lp:ubuntu/oneiric/dropbear
Proposed by
Julian Taylor
on 2012-04-24
| Status: | Rejected | ||||
|---|---|---|---|---|---|
| Rejected by: | Martin Pitt on 2012-04-27 | ||||
| Proposed branch: | lp:~jtaylor/ubuntu/oneiric/dropbear/CVE-2012-0920 | ||||
| Merge into: | lp:ubuntu/oneiric/dropbear | ||||
| Diff against target: |
122 lines (+110/-0) 2 files modified
debian/changelog (+10/-0) debian/diff/0003-Fix-use-after-free-bug-CVE-2012-0920.diff (+100/-0) |
||||
| To merge this branch: | bzr merge lp:~jtaylor/ubuntu/oneiric/dropbear/CVE-2012-0920 | ||||
| Related bugs: |
|
| Reviewer | Review Type | Date Requested | Status |
|---|---|---|---|
| Jamie Strandboge | Approve on 2012-04-26 | ||
| Ubuntu branches | 2012-04-24 | Pending | |
|
Review via email:
|
|||
Description of the Change
patch from upstream 2012.55 applies to oneiric, fuzz svr-chansession.c irrelevant
To post a comment you must log in.
Unmerged revisions
- 17. By Julian Taylor on 2012-04-24
-
* SECURITY UPDATE: remote execution via use after free (LP: #976360)
- debian/diff/0003- Fix-use- after-free- bug-CVE- 2012-0920. diff
pulled from https://secure. ucc.asn. au/hg/dropbear/ rev/818108bf774 9
Thanks to Matt Johnston
- CVE-2012-0920


Oneiric should use a patch name of 0004-Fix- use-after- free-bug- CVE-2012- 0920.diff since 0004 already exists. I fixed this.