oss-sec mailing list archives
Re: MFSA 2009-63
From: Reed Loden <reed () reedloden com>
Date: Thu, 29 Oct 2009 15:35:08 -0500
On Thu, 29 Oct 2009 21:22:44 +0100 Tomas Hoger <thoger () redhat com> wrote:
Has anyone been looking into MFSA 2009-63 already trying to figure out what really got fixed? We have some notes in: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3379 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3377 but I'm still not quite convinced we have a full list of upstream commits that need backporting. Has anyone got any further already?
What type of specific information are you looking for? Mozilla works with upstream Xiph.org to get such issues resolved upstream, and then we either take a minimal fix downstream or a full library upgrade to latest upstream code. Lately, we've been having to do full library upgrades due to the complexity of fixes and dependencies on other changes. I'll see if we can get those still private bugs concerning the media library fixes open sooner rather than later, though. I can probably CC you (and possibly others) to the bugs quicker than that, if it would help. ~reed Mozilla Security Group -- Reed Loden - <reed () reedloden com>
Attachment:
_bin
Description:
Current thread:
- MFSA 2009-63 Tomas Hoger (Oct 29)
- Re: MFSA 2009-63 Reed Loden (Oct 29)
- Re: MFSA 2009-63 Florian Weimer (Oct 29)
- Re: MFSA 2009-63 Reed Loden (Oct 29)
- Re: MFSA 2009-63 Tomas Hoger (Oct 30)
- Re: MFSA 2009-63 Reed Loden (Oct 30)
- Re: MFSA 2009-63 Tomas Hoger (Oct 30)
- Re: MFSA 2009-63 Florian Weimer (Oct 29)
- Re: MFSA 2009-63 Reed Loden (Oct 29)