Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.maint.python > #16495

Re: python-werkzeug CVEs

From Sean Whitton <spwhitton@spwhitton.name>
Newsgroups linux.debian.maint.python
Subject Re: python-werkzeug CVEs
Date 2024-11-29 09:40 +0100
Message-ID <JO4HE-cqeB-17@gated-at.bofh.it> (permalink)
References <JNZRD-cmec-1@gated-at.bofh.it> <JO3Lz-cppV-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hello,

On Fri 29 Nov 2024 at 08:38am +01, Carsten Schoenert wrote:

> Hi Sean,
>
> Am 29.11.24 um 04:22 schrieb Sean Whitton:
>> Hello,
>> There are three DoS CVEs for python-werkzeug in stable.
>> I intend to fix these as part of the Debian LTS team, sponsored by
>> Freexian.  I would like also to fix them in bookworm, because that will
>> become an LTS release eventually.  Would you like me to go ahead and
>> submit a stable update request, or are you already working on something?
>
> no, I haven't looked into the details yet to fix these CVEs for the older
> versions in Debian, I was intending to look into these after the recent happen
> update of Werkzeug plus Flask *and* after my moving of home. It would take at
> least some more weeks on my sid, please go ahead and don't wait for me.

Thanks for getting back to me so quickly.  I'll see how I get on.

-- 
Sean Whitton

Back to linux.debian.maint.python | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

python-werkzeug CVEs Sean Whitton <spwhitton@spwhitton.name> - 2024-11-29 04:30 +0100
  Re: python-werkzeug CVEs Carsten Schoenert <c.schoenert@t-online.de> - 2024-11-29 08:40 +0100
    Re: python-werkzeug CVEs Sean Whitton <spwhitton@spwhitton.name> - 2024-11-29 09:40 +0100

csiph-web