Abhijith PA pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
18a179d1 by Abhijith PA at 2020-03-21T21:08:23+05:30
Codebase have changed substantially, API changes. Backporting can be
too intrusive and not worth it as AJP is disabled in the default
installations.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -21601,6 +21601,7 @@ CVE-2020-1938 (When using the Apache JServ Protocol 
(AJP), care must be taken wh
        {DLA-2133-1}
        - tomcat9 9.0.31-1 (bug #952437)
        - tomcat8 <removed> (bug #952438)
+       [jessie] - tomcat8 <no-dsa> (backport is intrusive because of API 
changes)
        - tomcat7 <removed> (bug #952436)
        NOTE: AJP disabled in Debian in default configuration since 2008
        NOTE: fixed in upstream versions 9.0.31, 8.5.51, 7.0.100



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18a179d1e88e704c4a29a3944d79d6deb4e6c8f3

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18a179d1e88e704c4a29a3944d79d6deb4e6c8f3
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to