[Git][security-tracker-team/security-tracker][master] CVE-2015-2156/netty: precise jessie triage, link final patch

Sylvain Beucler beuc at debian.org
Mon Feb 17 17:48:12 GMT 2020



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d0acb0e9 by Sylvain Beucler at 2020-02-17T18:46:21+01:00
CVE-2015-2156/netty: precise jessie triage, link final patch

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -232812,16 +232812,16 @@ CVE-2015-2156 (Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x befor
 	- netty3.1 <removed>
 	[wheezy] - netty3.1 <no-dsa> (Minor issue)
 	- netty 1:4.0.31-1 (bug #796114)
-	[jessie] - netty <no-dsa> (Minor issue)
+	[jessie] - netty <ignored> (Minor issue, invasive patch)
 	[wheezy] - netty <no-dsa> (Minor issue)
 	- netty-3.9 3.9.9.Final-1 (bug #793770)
-	[jessie] - netty-3.9 <no-dsa> (Minor issue)
+	[jessie] - netty-3.9 <ignored> (Minor issue, invasive patch)
 	- playframework <itp> (bug #646523)
 	[squeeze] - netty <no-dsa> (Minor issue)
 	NOTE: http://netty.io/news/2015/05/08/3-9-8-Final-and-3.html
 	NOTE: https://www.playframework.com/security/vulnerability/CVE-2015-2156-HttpOnlyBypass
 	NOTE: http://web.archive.org/web/20150925094949/http://engineering.linkedin.com/security/look-netty%E2%80%99s-recent-security-update-cve%C2%AD-2015%C2%AD-2156
-	NOTE: https://github.com/slandelle/netty/commit/800555417e77029dcf8a31d7de44f27b5a8f79b8
+	NOTE: https://github.com/netty/netty/commit/97d871a7553a01384b43df855dccdda5205ae77a
 CVE-2015-2155 (The force printer in tcpdump before 4.7.2 allows remote attackers to c ...)
 	{DSA-3193-1 DLA-174-1}
 	- tcpdump 4.6.2-4



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/d0acb0e92169ee56161f6eca0d29e8ff62bb2c9e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/d0acb0e92169ee56161f6eca0d29e8ff62bb2c9e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200217/b7ed37bb/attachment.html>


More information about the debian-security-tracker-commits mailing list