Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

Simon McVittie smcv at debian.org
Sat Aug 12 20:22:06 UTC 2017


On Sat, 12 Aug 2017 at 15:33:34 +0200, Moritz Mühlenhoff wrote:
> Feel free to simply upload an untested package for jessie-security,
> I'm flying back on Sunday evening, I can run tests on jessie sometime
> next week.

I was able to do a smoke-test on a virtual machine (llvmpipe is much
better than I remembered, apparently) so there is now a briefly tested
jessie-security version in the queue. Any additional testing would
likely be useful - the patch is to netcode, so hosting or joining an
openarena server is an appropriate test. See attached debdiff.

    S
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ioquake3_1.36+u20140802+gca9eebb-2+deb8u2.diff
Type: text/x-diff
Size: 9456 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-games-devel/attachments/20170812/2a669fc6/attachment.diff>


More information about the Pkg-games-devel mailing list