Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker
Commits: 2985624f by Ola Lundqvist at 2021-03-18T22:07:54+01:00 Giving package to someone else to conclude. - - - - - 1 changed file: - data/dla-needed.txt Changes: ===================================== data/dla-needed.txt ===================================== @@ -47,12 +47,13 @@ golang-github-appc-cni (Thorsten Alteholz) NOTE: 20210221: also taking care of reverse dependencies NOTE: 20210221: also taking care of other suites -- -golang-gogoprotobuf (Ola Lundqvist) +golang-gogoprotobuf NOTE: 20210218: If you have any idea why this is called the "skippy peanut butter" issue, I would be mildly interested. (lamby) NOTE: 20210308: The only explanation I have is that Skippy is a peanut butter brand and the fix is related to a variable called skippy (Ola) NOTE: 20210308: Patch prepared and available http://apt.inguza.net/stretch-lts/golang-gogoprotobuf/CVE-2021-3121-1.patch NOTE: 20210308: If anyone have a good way to regression test the package this information is appreciated. NOTE: 20210308: If anyone have information on what the result of the missing range check is, that information is also appreciated. + NOTE: 20210318: The generated code is in many other go packages. -- gsoap -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2985624f8ed4ba3e55e3125feb0095de6e4af8a9 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2985624f8ed4ba3e55e3125feb0095de6e4af8a9 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits