[Git][security-tracker-team/security-tracker][master] Explicitly track the fix for CVE-2018-16470/ruby-rack in experimental

Salvatore Bonaccorso carnil at debian.org
Fri Jan 4 09:42:25 GMT 2019


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
613028b6 by Salvatore Bonaccorso at 2019-01-04T09:41:27Z
Explicitly track the fix for CVE-2018-16470/ruby-rack in experimental

The issue was only introduced in 2.0.4 and thus never affected sid as
already recorded. For keeping the information mark the fixed version for
experimental as well.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -20858,7 +20858,7 @@ CVE-2018-16471 (There is a possible XSS vulnerability in Rack before 2.0.6 and 1
 	NOTE: Fixed by: https://github.com/rack/rack/commit/313dd6a05a5924ed6c82072299c53fed09e39ae7 (2.0.6)
 	NOTE: Fixed by: https://github.com/rack/rack/commit/97ca63d87d88b4088fb1995b14103d4fe6a5e594 (1.6.11)
 CVE-2018-16470 (There is a possible DoS vulnerability in the multipart parser in Rack ...)
-	[experimental] - ruby-rack <unfixed> (bug #913003)
+	[experimental] - ruby-rack 2.0.6-1 (bug #913003)
 	- ruby-rack <not-affected> (Only affects >= 2.0.4)
 	NOTE: Introduced by: https://github.com/rack/rack/commit/c43217a81917de03aa6ceb1aa485ae69b8bb4598 (2.0.4)
 	NOTE: Fixed by: https://github.com/rack/rack/commit/37c1160b2360074d20858792f23a7eb3afeabebd (2.0.6)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/613028b6bf09ad6ce250afb0e906ec1ebddc1794

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/613028b6bf09ad6ce250afb0e906ec1ebddc1794
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190104/6ccbca2b/attachment.html>


More information about the debian-security-tracker-commits mailing list