tags 977805 + security buster sid
thanks

There is a security angle to this FTBFS.  Because ntopng is currently
unable to build against ndpi 3.4, it still links against ndpi 3.0, a
known vulnerable version, and users of ntopng are thus getting this
vulnerable ndpi 3.0 library.

ndpi (3.4-1) unstable; urgency=medium
[...]
  * New upstream version 3.4 (Closes: #972050)
    - CVE-2020-11939 CVE-2020-11940 CVE-2020-15471
    - CVE-2020-15472 CVE-2020-15473 CVE-2020-15474
    - CVE-2020-15475 CVE-2020-15476

-Dan

Reply via email to