[Git][security-tracker-team/security-tracker][master] CVE-2025-46806/sslh: Link to the second part of the fix

Adrian Bunk (@bunk) bunk at debian.org
Fri Jun 20 16:15:14 BST 2025



Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ab58bff9 by Adrian Bunk at 2025-06-20T18:13:37+03:00
CVE-2025-46806/sslh: Link to the second part of the fix

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6189,6 +6189,8 @@ CVE-2025-46806 (A Use of Out-of-range Pointer Offset vulnerability in sslh leads
 	- sslh <unfixed> (bug #1107214)
 	NOTE: https://bugzilla.suse.com/show_bug.cgi?id=1243120
 	NOTE: Fixed by: https://github.com/yrutschle/sslh/commit/204305a88fb32cffaf1349253a2b052186ca8d39 (v2.2.4)
+	NOTE: Original fix in 2.2.4 was incomplete.
+	NOTE: Fixed by: https://github.com/yrutschle/sslh/commit/cd9b85fd4f2dafe4eab01c9d9c0706f00d81c12a
 	NOTE: https://www.openwall.com/lists/oss-security/2025/06/13/1
 CVE-2025-45542 (SQL injection vulnerability in the registrationform endpoint of CloudC ...)
 	NOT-FOR-US: CloudClassroom-PHP-Project



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab58bff91572b6dbb13d822019ac38ed86c51a4d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab58bff91572b6dbb13d822019ac38ed86c51a4d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250620/60fb9571/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list