[Git][security-tracker-team/security-tracker][master] Codebase have changed substantially, API changes. Backporting can be

Abhijith PA abhijith at debian.org
Sat Mar 21 15:45:03 GMT 2020



Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker


Commits:
18a179d1 by Abhijith PA at 2020-03-21T21:08:23+05:30
Codebase have changed substantially, API changes. Backporting can be
too intrusive and not worth it as AJP is disabled in the default
installations.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -21601,6 +21601,7 @@ CVE-2020-1938 (When using the Apache JServ Protocol (AJP), care must be taken wh
 	{DLA-2133-1}
 	- tomcat9 9.0.31-1 (bug #952437)
 	- tomcat8 <removed> (bug #952438)
+	[jessie] - tomcat8 <no-dsa> (backport is intrusive because of API changes)
 	- tomcat7 <removed> (bug #952436)
 	NOTE: AJP disabled in Debian in default configuration since 2008
 	NOTE: fixed in upstream versions 9.0.31, 8.5.51, 7.0.100



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18a179d1e88e704c4a29a3944d79d6deb4e6c8f3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18a179d1e88e704c4a29a3944d79d6deb4e6c8f3
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200321/eb8b2695/attachment.html>


More information about the debian-security-tracker-commits mailing list