Bug#896548: gunicorn: CVE-2018-1000164

2018-04-29 Thread Moritz Mühlenhoff
On Mon, Apr 23, 2018 at 12:41:31PM +0100, Chris Lamb wrote: > Hi Moritz, > > > > > gunicorn: CVE-2018-1000164 > > > > > > I've prepared an upload for jessie. Permission to upload? :) > > > > Thanks, please upload. > > gunicorn_19.0-1+deb8u1_amd64.changes uploaded. Released yesterday, thanks.

Bug#896548: gunicorn: CVE-2018-1000164

2018-04-23 Thread Chris Lamb
Hi Moritz, > > > gunicorn: CVE-2018-1000164 > > > > I've prepared an upload for jessie. Permission to upload? :) > > Thanks, please upload. gunicorn_19.0-1+deb8u1_amd64.changes uploaded. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org /

Bug#896548: gunicorn: CVE-2018-1000164

2018-04-23 Thread Moritz Muehlenhoff
On Sun, Apr 22, 2018 at 10:17:28AM +0100, Chris Lamb wrote: > Hi security team, > > > gunicorn: CVE-2018-1000164 > > I've prepared an upload for jessie. Permission to upload? :) Thanks, please upload. Cheers, Moritz

Bug#896548: gunicorn: CVE-2018-1000164

2018-04-22 Thread Chris Lamb
Hi security team, > gunicorn: CVE-2018-1000164 I've prepared an upload for jessie. Permission to upload? :) changelog |8 patches/CVE-2018-1000164.patch | 38 ++ patches/series |1 + 3 files

Bug#896548: gunicorn: CVE-2018-1000164

2018-04-22 Thread Chris Lamb
Package: gunicorn Version: 0.14.5-3+deb7u1 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for gunicorn. CVE-2018-1000164[0]: | gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of | CRLF Sequences in HTTP