|
From: Steven L. <sr...@ic...> - 2016-07-07 16:13:45
|
Hello, 1. *for all patches contributed to ICU* please follow the link at the bottom http://bugs.icu-project.org/trac/ticket/12276#cla and ensure you’ve signed the CLA. 2. I own the ticket, but had not responded to this yet. 3. The patches look good. The “signed overflow” in the compile options was unexpected and may need some evaluation. (I wrote and/or reviewed the OpenJDK side patches) Steven El 7/7/16 5:48 AM, "Roberto C. Sánchez" <ro...@co...> escribió: >Hello, > >I posted the below to trac [0] last week: > >---------------------------------------- >Greetings. I have prepared patches for the Debian package of ICU 4.8.1.1 >(in Wheezy, or the oldstable distribution, 7.11) that cover >CVE-2015-2632, CVE-2015-4844, and CVE-2016-0494. They are based on >specific commits to the OpenJDK upstream source. I would like to upload >the patched ICU to Debian Wheezy in order to address the stated CVEs. >Would it be possible for someone from upstream, who is more familiar >with the inner workings of ICU, to review the patches? >---------------------------------------- > >I have not yet received a reply, so I decided to post here to the list >to inquire if this is in fact the correct approach to get the patches >reviewed or to see if someone who hasn't seen the trac ticket might be >able to assist me. > >Regards, > >-Roberto > >[0] http://bugs.icu-project.org/trac/ticket/12276 > >-- >Roberto C. Sánchez >http://people.connexer.com/~roberto >http://www.connexer.com > >------------------------------------------------------------------------------ >Attend Shape: An AT&T Tech Expo July 15-16. Meet us at AT&T Park in San >Francisco, CA to explore cutting-edge tech and listen to tech luminaries >present their vision of the future. This family event has something for >everyone, including kids. Get more information and register today. >http://sdm.link/attshape >_______________________________________________ >icu-support mailing list - icu...@li... >To Un/Subscribe: https://lists.sourceforge.net/lists/listinfo/icu-support >Archives/Project Info: http://site.icu-project.org/contacts |