Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker
Commits: 1cb1b17e by Tobias Frost at 2024-01-16T06:03:39+01:00 Remove paramiko from dla-needed.txt CVE-2023-48795/paramiko buster is not vulnerable. Confirmed by upstream: https://github.com/paramiko/paramiko/issues/2337#issuecomment-1880185735 paramiko 2.4.2 does neither implement ETM-Mac modes nor ChaCha20. It also has no EXT_INFO support, which might be a factor for exploitability. - - - - - 1 changed file: - data/dla-needed.txt Changes: ===================================== data/dla-needed.txt ===================================== @@ -165,9 +165,6 @@ nvidia-cuda-toolkit NOTE: 20230610: Details: https://lists.debian.org/debian-lts/2023/06/msg00032.html NOTE: 20230610: my recommendation would be to put the package on the "not-supported" list. (tobi) -- -paramiko (tobi) - NOTE: 20231225: Added by Front-Desk (ta) --- php-phpseclib (guilhem) NOTE: 20240114: Added by Front-Desk (apo) -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1cb1b17e6728cb9da9a0a3a77f80bb3a18f9d1ab -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1cb1b17e6728cb9da9a0a3a77f80bb3a18f9d1ab You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits