Bug#1021737: lava: CVE-2022-42902

2022-10-21 Thread Antonio Terceiro
On Wed, Oct 19, 2022 at 09:57:34PM +0200, Moritz Muehlenhoff wrote: > On Tue, Oct 18, 2022 at 06:09:42PM -0300, Antonio Terceiro wrote: > > Hi, > > > > On Thu, Oct 13, 2022 at 09:13:18PM +0200, Moritz Mühlenhoff wrote: > > > Source: lava > > > X-Debbugs-CC: t...@security.debian.org > > > Severity:

Bug#1021737: lava: CVE-2022-42902

2022-10-19 Thread Moritz Muehlenhoff
On Tue, Oct 18, 2022 at 06:09:42PM -0300, Antonio Terceiro wrote: > Hi, > > On Thu, Oct 13, 2022 at 09:13:18PM +0200, Moritz Mühlenhoff wrote: > > Source: lava > > X-Debbugs-CC: t...@security.debian.org > > Severity: grave > > Tags: security > > > > Hi, > > > > The following vulnerability was pu

Bug#1021737: lava: CVE-2022-42902

2022-10-18 Thread Antonio Terceiro
On Tue, Oct 18, 2022 at 06:09:45PM -0300, Antonio Terceiro wrote: > Hi, > > On Thu, Oct 13, 2022 at 09:13:18PM +0200, Moritz Mühlenhoff wrote: > > Source: lava > > X-Debbugs-CC: t...@security.debian.org > > Severity: grave > > Tags: security > > > > Hi, > > > > The following vulnerability was pu

Bug#1021737: lava: CVE-2022-42902

2022-10-18 Thread Antonio Terceiro
Hi, On Thu, Oct 13, 2022 at 09:13:18PM +0200, Moritz Mühlenhoff wrote: > Source: lava > X-Debbugs-CC: t...@security.debian.org > Severity: grave > Tags: security > > Hi, > > The following vulnerability was published for lava. > > CVE-2022-42902[0]: > | In Linaro Automated Validation Architectur

Bug#1021737: lava: CVE-2022-42902

2022-10-13 Thread Moritz Mühlenhoff
Source: lava X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for lava. CVE-2022-42902[0]: | In Linaro Automated Validation Architecture (LAVA) before 2022.10, | there is dynamic code execution in lava_server/lavatable.py. Due to