Bug#1141398: trixie-pu: package starman/0.4018-0+deb13u1
Salvatore Bonaccorso
carnil at debian.org
Fri Jul 3 22:09:04 BST 2026
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: starman at packages.debian.org, debian-perl at lists.debian.org, gregoa at debian.org, bunk at debian.org, team at security.debian.org, carnil at debian.org
Control: affects -1 + src:starman
User: release.debian.org at packages.debian.org
Usertags: pu
Hi
starman in trixie was prone to CVE-2026-40560 and got fixed for forky
with a new upstream version 0.4018. The only changes between 0.4017 as
in trixie and the fixed version was the security fix *and* some
documentation fixes. So we opted to just import 0.4018 in trixie as
well.
| * Import upstream version 0.4018.
| - Fix HTTP request smuggling: Transfer-Encoding now takes precedence
| over Content-Length per RFC 7230 §3.3.3 (CVE-2026-40560)
| Closes: #1135229
Upload was tested on debusine under:
https://debusine.debian.net/debian/developers/work-request/904801/
Regards,
Salvatore
More information about the pkg-perl-maintainers
mailing list