Bug#1021739: nekohtml: CVE-2022-24839

2023-01-28 Thread tony mancill
On Sat, Jan 28, 2023 at 11:35:30PM +0100, David Prévot wrote: > Hi, > > Le Thu, Oct 13, 2022 at 09:17:02PM +0200, Moritz Mühlenhoff a écrit : > > Source: nekohtml > […] > > The following vulnerability was published for nekohtml. > > > > CVE-2022-24839[0]: > > I prepared an upload (new upstream

Bug#1021739: nekohtml: CVE-2022-24839

2023-01-28 Thread David Prévot
Hi, Le Thu, Oct 13, 2022 at 09:17:02PM +0200, Moritz Mühlenhoff a écrit : > Source: nekohtml […] > The following vulnerability was published for nekohtml. > > CVE-2022-24839[0]: I prepared an upload (new upstream release) of this package in order to fix this RC-bug as part of the BSP currently

Bug#1021739: nekohtml: CVE-2022-24839

2022-10-13 Thread Moritz Mühlenhoff
Source: nekohtml X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for nekohtml. CVE-2022-24839[0]: | org.cyberneko.html is an html parser written in Java. The fork of | `org.cyberneko.html` used by Nokogiri (Rubygem) raises a |