Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
613028b6 by Salvatore Bonaccorso at 2019-01-04T09:41:27Z
Explicitly track the fix for CVE-2018-16470/ruby-rack in experimental
The issue was only introduced in 2.0.4 and thus never affected sid as
already recorded. For keeping the information mark the fixed version for
experimental as well.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -20858,7 +20858,7 @@ CVE-2018-16471 (There is a possible XSS vulnerability
in Rack before 2.0.6 and 1
NOTE: Fixed by:
https://github.com/rack/rack/commit/313dd6a05a5924ed6c82072299c53fed09e39ae7
(2.0.6)
NOTE: Fixed by:
https://github.com/rack/rack/commit/97ca63d87d88b4088fb1995b14103d4fe6a5e594
(1.6.11)
CVE-2018-16470 (There is a possible DoS vulnerability in the multipart parser
in Rack ...)
- [experimental] - ruby-rack <unfixed> (bug #913003)
+ [experimental] - ruby-rack 2.0.6-1 (bug #913003)
- ruby-rack <not-affected> (Only affects >= 2.0.4)
NOTE: Introduced by:
https://github.com/rack/rack/commit/c43217a81917de03aa6ceb1aa485ae69b8bb4598
(2.0.4)
NOTE: Fixed by:
https://github.com/rack/rack/commit/37c1160b2360074d20858792f23a7eb3afeabebd
(2.0.6)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/commit/613028b6bf09ad6ce250afb0e906ec1ebddc1794
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/commit/613028b6bf09ad6ce250afb0e906ec1ebddc1794
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits