[Git][security-tracker-team/security-tracker][master] Explicitly track the fix for CVE-2018-16470/ruby-rack in experimental
Salvatore Bonaccorso
carnil at debian.org
Fri Jan 4 09:42:25 GMT 2019
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
613028b6 by Salvatore Bonaccorso at 2019-01-04T09:41:27Z
Explicitly track the fix for CVE-2018-16470/ruby-rack in experimental
The issue was only introduced in 2.0.4 and thus never affected sid as
already recorded. For keeping the information mark the fixed version for
experimental as well.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -20858,7 +20858,7 @@ CVE-2018-16471 (There is a possible XSS vulnerability in Rack before 2.0.6 and 1
NOTE: Fixed by: https://github.com/rack/rack/commit/313dd6a05a5924ed6c82072299c53fed09e39ae7 (2.0.6)
NOTE: Fixed by: https://github.com/rack/rack/commit/97ca63d87d88b4088fb1995b14103d4fe6a5e594 (1.6.11)
CVE-2018-16470 (There is a possible DoS vulnerability in the multipart parser in Rack ...)
- [experimental] - ruby-rack <unfixed> (bug #913003)
+ [experimental] - ruby-rack 2.0.6-1 (bug #913003)
- ruby-rack <not-affected> (Only affects >= 2.0.4)
NOTE: Introduced by: https://github.com/rack/rack/commit/c43217a81917de03aa6ceb1aa485ae69b8bb4598 (2.0.4)
NOTE: Fixed by: https://github.com/rack/rack/commit/37c1160b2360074d20858792f23a7eb3afeabebd (2.0.6)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/613028b6bf09ad6ce250afb0e906ec1ebddc1794
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/613028b6bf09ad6ce250afb0e906ec1ebddc1794
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190104/6ccbca2b/attachment.html>
More information about the debian-security-tracker-commits
mailing list