security fixes for 2.5.6

Josh Bressers bressers at redhat.com
Thu May 14 12:34:17 EDT 2009


----- "Stanislav Brabec" <sbrabec at suse.cz> wrote:
> Ka-Hing Cheung wrote:
> 
> > Additionally, the previous fix to CVE-2008-2927 was incomplete, so we
> > fixed it again:
> > 
> > 9dd1c4c3 Fixes a buffer overflow in the ZDI-08-054 report
> 
> Shouldn't be the same done for both msn and msnp9? The patch applies to both
> branches.
> 

So FWIW, I looked at Red Hat's build log of this. We don't ever build the
source in that directory.

Thanks.

-- 
    JB



More information about the Packagers mailing list