Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker
Commits: 16b2d4ed by Guilhem Moulin at 2023-10-16T01:10:02+02:00 Fix sid version for CVE-2018-25091/python-urllib3. The first version ≥1.25.2 that landed in unstable is 1.25.6-4 no 1.25.6-1 (which was uploaded to experimental only). - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -2,10 +2,10 @@ CVE-2023-38312 (A directory traversal vulnerability in Valve Counter-Strike 8684 TODO: check CVE-2018-25091 (urllib3 before 1.24.2 does not remove the authorization HTTP header wh ...) {DLA-3610-1} - - python-urllib3 1.25.6-1 + - python-urllib3 1.25.6-4 NOTE: https://github.com/urllib3/urllib3/issues/1510 NOTE: This issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive). - NOTE: Fixed by https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc (1.24.2) + NOTE: Fixed by https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc (1.25) CVE-2023-5586 (NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0 ...) TODO: check CVE-2023-5585 (A vulnerability was found in SourceCodester Online Motorcycle Rental S ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/16b2d4ed19004e39e5ac274364d1377089712b45 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/16b2d4ed19004e39e5ac274364d1377089712b45 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits