oss-sec mailing list archives

Re: MFSA 2009-63


From: Reed Loden <reed () reedloden com>
Date: Thu, 29 Oct 2009 15:35:08 -0500

On Thu, 29 Oct 2009 21:22:44 +0100
Tomas Hoger <thoger () redhat com> wrote:

Has anyone been looking into MFSA 2009-63 already trying to figure out
what really got fixed?  We have some notes in:

  https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3379
  https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3377

but I'm still not quite convinced we have a full list of upstream
commits that need backporting.  Has anyone got any further already?

What type of specific information are you looking for? Mozilla works
with upstream Xiph.org to get such issues resolved upstream, and then
we either take a minimal fix downstream or a full library upgrade to
latest upstream code. Lately, we've been having to do full library
upgrades due to the complexity of fixes and dependencies on other
changes.

I'll see if we can get those still private bugs concerning the media
library fixes open sooner rather than later, though. I can probably CC
you (and possibly others) to the bugs quicker than that, if it would
help.

~reed
Mozilla Security Group

-- 
Reed Loden - <reed () reedloden com>

Attachment: _bin
Description:


Current thread: