Re: Apache's mod_remoteip: IP address spoofing via X-Forwarded-For when mod_rewrite rule is triggered

2020-05-09 Thread Utkarsh Gupta
Hi, On Sat, 2 May, 2020, 3:28 AM Ola Lundqvist, wrote: > Added the package to DLA needed. > Unless there's a CVE assigned for this, should I really be fixing it and announcing the update? Best, Utkarsh >

Re: Apache's mod_remoteip: IP address spoofing via X-Forwarded-For when mod_rewrite rule is triggered

2020-05-09 Thread Chris Lamb
Hi Utkarsh et al., > Unless there's a CVE assigned for this, should I really be fixing it > and announcing the update? This might be conflating cause and effect. Let me ask a question in return - did you consider applying for a CVE? If we cannot justify applying for one on grounds of severity th

Re: Triage of CVE-2020-9489/tika

2020-05-09 Thread Chris Lamb
Hi Utkarsh, I will first your mail in full with the Git SHAs expanded to URIs of the diffs themselves: > The general dependency updates including some with security > implications: https://github.com/apache/tika/commit/171f4343.diff > > The fixes for the security items identified in that CVE > h

LTS report for April 2020 - Abhijith PA

2020-05-09 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 April was my 26th month as a Debian LTS paid contributor.I was assigned 14 hours. I was only able to spent 10 hours. * apache-log4j2: Backporting CVE-2020-9488 needs backporting couple of java classes from upstream and is intrusive. Another fas