[Git][security-tracker-team/security-tracker][master] dla: Add jinja2 status from before the semi-automatic unclaim

Adrian Bunk (@bunk) bunk at debian.org
Wed Jan 22 20:02:32 GMT 2025



Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ab8c4ef2 by Adrian Bunk at 2025-01-22T22:01:54+02:00
dla: Add jinja2 status from before the semi-automatic unclaim

- - - - -


1 changed file:

- data/dla-needed.txt


Changes:

=====================================
data/dla-needed.txt
=====================================
@@ -136,6 +136,10 @@ jetty9 (Markus Koschany)
 jinja2 (Sean Whitton)
   NOTE: 20250105: Added by Front-Desk (apo)
   NOTE: 20240122: Updated sid, waiting for ci.debian.net results.  (spwhitton)
+  NOTE: 20240122: CVE-2024-56201 is not directly affected (no f-syntax in Python2),
+  NOTE: 20240122: to be double-checked whether similar vulnerability exists in the old code.
+  NOTE: 20240122: CVE-2024-56326 testcase does not work directly in bullseye.
+  NOTE: 20240122: Don't break the Python2 package again as I did (DLA-3988-2). (bunk)
 --
 knot-resolver
   NOTE: 20240924: Added by Front-Desk (lamby)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab8c4ef29eeef11a0ac1b6df2cf4b6d678b3697e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab8c4ef29eeef11a0ac1b6df2cf4b6d678b3697e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250122/633693c3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list