Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
613028b6 by Salvatore Bonaccorso at 2019-01-04T09:41:27Z
Explicitly track the fix for CVE-2018-16470/ruby-rack in experimental

The issue was only introduced in 2.0.4 and thus never affected sid as
already recorded. For keeping the information mark the fixed version for
experimental as well.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -20858,7 +20858,7 @@ CVE-2018-16471 (There is a possible XSS vulnerability 
in Rack before 2.0.6 and 1
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/313dd6a05a5924ed6c82072299c53fed09e39ae7 
(2.0.6)
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/97ca63d87d88b4088fb1995b14103d4fe6a5e594 
(1.6.11)
 CVE-2018-16470 (There is a possible DoS vulnerability in the multipart parser 
in Rack ...)
-       [experimental] - ruby-rack <unfixed> (bug #913003)
+       [experimental] - ruby-rack 2.0.6-1 (bug #913003)
        - ruby-rack <not-affected> (Only affects >= 2.0.4)
        NOTE: Introduced by: 
https://github.com/rack/rack/commit/c43217a81917de03aa6ceb1aa485ae69b8bb4598 
(2.0.4)
        NOTE: Fixed by: 
https://github.com/rack/rack/commit/37c1160b2360074d20858792f23a7eb3afeabebd 
(2.0.6)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/613028b6bf09ad6ce250afb0e906ec1ebddc1794

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/613028b6bf09ad6ce250afb0e906ec1ebddc1794
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to