[Git][security-tracker-team/security-tracker][master] Ignore CVE-2021-36740 (varnish) in stretch
Adrian Bunk (@bunk)
bunk at debian.org
Fri Aug 13 23:37:36 BST 2021
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ab1187d5 by Adrian Bunk at 2021-08-14T01:36:53+03:00
Ignore CVE-2021-36740 (varnish) in stretch
HTTP/2 support is marked experimental in 5.0 and enabling is not
recommended, code is quite different
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -4420,6 +4420,7 @@ CVE-2021-36727
RESERVED
CVE-2021-36740 (Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL a ...)
- varnish 6.5.2-1 (bug #991040)
+ [stretch] - varnish <ignored> (HTTP/2 support is marked experimental in 5.0 and enabling is not recommended, code is quite different)
NOTE: https://varnish-cache.org/security/VSV00007.html
NOTE: https://github.com/varnishcache/varnish-cache/commit/9be22198e258d0e7a5c41f4291792214a29405cf (6.0.8)
NOTE: https://github.com/varnishcache/varnish-cache/commit/82b0a629f60136e76112c6f2c6372cce77b683be (6.5.2)
=====================================
data/dla-needed.txt
=====================================
@@ -101,5 +101,3 @@ thunderbird (Emilio)
usermode (Utkarsh Gupta)
NOTE: 20210803: See "Subject: packages in *-lts newer than in subsequent releases"
--
-varnish (Adrian Bunk)
---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab1187d5b0ce63650fce3efba8230508541fb757
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab1187d5b0ce63650fce3efba8230508541fb757
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210813/c1668c24/attachment.htm>
More information about the debian-security-tracker-commits
mailing list