Bug#992786: passenger uses many vendored libraries

2022-06-01 Thread Antonio Terceiro
Control: severity -1 important Hi, On Mon, Aug 23, 2021 at 03:00:16PM +0300, Adrian Bunk wrote: > Source: passenger > Severity: serious > > passenger-5.0.30/src/cxx_supportlib/vendor-copy: > adhoc_lve.h libcurl libuv nghttp2 utf8 utf8.h > >

Processed: Re: Bug#992786: passenger uses many vendored libraries

2022-06-01 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #992786 [src:passenger] passenger uses many vendored libraries Severity set to 'important' from 'serious' -- 992786: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=992786 Debian Bug Tracking System Contact ow...@bugs.debian.org with

Bug#992786: passenger uses many vendored libraries

2021-08-25 Thread Adrian Bunk
On Mon, Aug 23, 2021 at 08:18:42AM -0400, Michael Lazin wrote: > I am new to this list and would like to get involved, but I am a relative > beginner in programming. I understand from looking at this CVE that it is > triggered by a particular type of API call, which is probably unlikely in > the

Bug#992786: passenger uses many vendored libraries

2021-08-23 Thread Michael Lazin
I am new to this list and would like to get involved, but I am a relative beginner in programming. I understand from looking at this CVE that it is triggered by a particular type of API call, which is probably unlikely in the wild, unless prior recon has been done and there is already a threat

Bug#992786: passenger uses many vendored libraries

2021-08-23 Thread Adrian Bunk
Source: passenger Severity: serious passenger-5.0.30/src/cxx_supportlib/vendor-copy: adhoc_lve.h libcurl libuv nghttp2 utf8 utf8.h passenger-5.0.30/src/cxx_supportlib/vendor-modified: SmallVector.h jsoncpp modp_b64.cpp modp_b64_data.h boost libevmodp_b64.hpsg_sysqueue.h