Re: DLA 1842-1: use of wrong CVE?

2019-07-02 Thread Martin Waleczek
Am 02.07.19 um 14:30 schrieb Chris Lamb: > This is "merely" cosmetic however; we are recording this > correctly internally in our database. Sure, thanks for the pull request anyway. Some time (years) ago someone from NVD made us aware of a misused CVE-ID on our side (we - German NREN - write publ

Re: DLA 1842-1: use of wrong CVE?

2019-07-02 Thread Chris Lamb
[Adding debian-lts@lists.debian.org to CC] Hi Martin, > from the vulnerability description in DLA 1842-1 I assume that the > CVE-ID mentioned is not correct. Should be the new CVE-2019-12781 from > > > https://www.djangoproject.com/weblog/2019/jul/01/security-releases/ > > instead of CVE-2019-1