Bug#964274: ruby-websocket-extensions: CVE-2020-7663

2021-05-05 Thread Salvatore Bonaccorso
Hi Andreas, On Wed, May 05, 2021 at 09:57:09PM +0200, Andreas Beckmann wrote: > Followup-For: Bug #964274 > > Hi, > > CVE-2020-7663 is fixed in stretch-security but not buster, making > upgrades difficult since stetch-security has a newer version than buster. > Please upload the fix to buster,

Bug#964274: ruby-websocket-extensions: CVE-2020-7663

2021-05-05 Thread Andreas Beckmann
Followup-For: Bug #964274 Hi, CVE-2020-7663 is fixed in stretch-security but not buster, making upgrades difficult since stetch-security has a newer version than buster. Please upload the fix to buster, too. ruby-websocket-extensions | 0.1.2-1| stretch | source, all

Bug#964274: ruby-websocket-extensions: CVE-2020-7663

2020-07-04 Thread Salvatore Bonaccorso
Source: ruby-websocket-extensions Version: 0.1.2-1 Severity: grave Tags: security upstream Hi, The following vulnerability was published for ruby-websocket-extensions. CVE-2020-7663[0]: | websocket-extensions ruby module prior to 0.1.5 allows Denial of | Service (DoS) via Regex Backtracking.