Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

Simon McVittie smcv at debian.org
Sat Aug 5 11:24:19 UTC 2017


Control: clone -1 -2
Control: reassign -2 src:iortcw
Control: forwarded -2 https://github.com/iortcw/iortcw/commit/260c39a29af517a08b3ee1a0e78ad654bdd70934
Control: found -2 1.51+dfsg1-2
Control: fixed -2 1.51+dfsg1-3

On Sat, 05 Aug 2017 at 11:47:23 +0100, Simon McVittie wrote:
> On Fri, 04 Aug 2017 at 16:30:46 +0200, Moritz Muehlenhoff wrote:
> > Please see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11721

iortcw in contrib also has this. I've uploaded a fix.

Again, I don't have time to handle this for stable right now, so
security or games team members are very welcome to do so. I'll prepare
a stable update during Debconf if nobody gets there first, assuming I
can find a stable user willing to test a game from contrib.

    S



More information about the Pkg-games-devel mailing list