[Git][security-tracker-team/security-tracker][master] Ignore CVE-2021-36740 (varnish) in stretch

Adrian Bunk (@bunk) bunk at debian.org
Fri Aug 13 23:37:36 BST 2021



Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ab1187d5 by Adrian Bunk at 2021-08-14T01:36:53+03:00
Ignore CVE-2021-36740 (varnish) in stretch

HTTP/2 support is marked experimental in 5.0 and enabling is not
recommended, code is quite different

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -4420,6 +4420,7 @@ CVE-2021-36727
 	RESERVED
 CVE-2021-36740 (Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL a ...)
 	- varnish 6.5.2-1 (bug #991040)
+	[stretch] - varnish <ignored> (HTTP/2 support is marked experimental in 5.0 and enabling is not recommended, code is quite different)
 	NOTE: https://varnish-cache.org/security/VSV00007.html
 	NOTE: https://github.com/varnishcache/varnish-cache/commit/9be22198e258d0e7a5c41f4291792214a29405cf (6.0.8)
 	NOTE: https://github.com/varnishcache/varnish-cache/commit/82b0a629f60136e76112c6f2c6372cce77b683be (6.5.2)


=====================================
data/dla-needed.txt
=====================================
@@ -101,5 +101,3 @@ thunderbird (Emilio)
 usermode (Utkarsh Gupta)
   NOTE: 20210803: See "Subject: packages in *-lts newer than in subsequent releases"
 --
-varnish (Adrian Bunk)
---



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab1187d5b0ce63650fce3efba8230508541fb757

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab1187d5b0ce63650fce3efba8230508541fb757
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210813/c1668c24/attachment.htm>


More information about the debian-security-tracker-commits mailing list