[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: LTS/subversion note



Hi Roberto,

> I decided to take a shot fixing CVE-2018-11782 and CVE-2019-0203 for
> subversion in jessie.  You had made the following note in
> dla-needed.txt:
> 
> subversion
>   NOTE: 20190804: For (at least) CVE-2018-11782 the svn_err_trace that 
> is in the diff has not been added yet. (lamby)
[…]
> In any event, what puzzled me was your mention of svn_err_trace in the
> diff.  I found no such function or type in either diff.

Another very quick glance suggests that it was "svn_error_trace".

I apologise if I misled you into thinking you should focus your time and
energy on that.

... but this makes me ponder that my notes tend to be scribbled quite
quickly, the only goal of them being to potentially save someone (or
myself) some time looking in the right place or perhaps confirming
their own investigation, rather than being something that can be 110%
trusted or otherwise treated as gospel. I'd rather write a note,
however unconfirmed, than not, if you see what I mean.


Best wishes,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org 🍥 chris-lamb.co.uk
       `-


Reply to: