Bug#1092774: libfcgi: CVE-2025-23016

2025-04-14 Thread Bastian Germann
Control: tags -1 fixed-upstream Please note that Yadd's debdiff is based on a patch that was rejected. The final solution was just released with the new upstream version 2.4.5: https://github.com/FastCGI-Archives/fcgi2/commit/b0eabcaf4d4f371514891a52115c746815c2ff15

Bug#1092774: libfcgi: CVE-2025-23016

2025-04-13 Thread Salvatore Bonaccorso
Hi Chris, On Sun, Apr 13, 2025 at 08:06:18PM +0200, Chris Hofstaedtler wrote: > On Sat, Jan 11, 2025 at 03:00:45PM +0100, Salvatore Bonaccorso wrote: > > Source: libfcgi > > Version: 2.4.2-2.1 > > Severity: grave > > Tags: security upstream > > Forwarded: https://github.com/FastCGI-Archives/fcgi2/

Bug#1092774: libfcgi: CVE-2025-23016

2025-04-13 Thread Chris Hofstaedtler
On Sat, Jan 11, 2025 at 03:00:45PM +0100, Salvatore Bonaccorso wrote: > Source: libfcgi > Version: 2.4.2-2.1 > Severity: grave > Tags: security upstream > Forwarded: https://github.com/FastCGI-Archives/fcgi2/issues/67 In the upstream bug there seems to be some disagreement if this is actually a p

Bug#1092774: libfcgi: CVE-2025-23016

2025-01-11 Thread Salvatore Bonaccorso
Source: libfcgi Version: 2.4.2-2.1 Severity: grave Tags: security upstream Forwarded: https://github.com/FastCGI-Archives/fcgi2/issues/67 X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: found -1 2.4.2-2 Hi, The following vulnerability was published for libfcgi. CVE-2025-23016[0]: