Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.maint.python > #16527

Bug#1089079: bookworm-pu: package python-werkzeug/2.2.2-3+deb12u1

Path csiph.com!fu-berlin.de!bofh.it!news.nic.it!robomod
From Sean Whitton <spwhitton@spwhitton.name>
Newsgroups linux.debian.bugs.dist, linux.debian.maint.python, linux.debian.devel.release
Subject Bug#1089079: bookworm-pu: package python-werkzeug/2.2.2-3+deb12u1
Date Thu, 05 Dec 2024 05:10:01 +0100
Message-ID <JQblD-dPCa-1@gated-at.bofh.it> (permalink)
X-Mailbox-Line From debian-bugs-dist-request@lists.debian.org Thu Dec 5 04:00:16 2024
Old-Return-Path <debbugs@buxtehude.debian.org>
X-Spam-Flag NO
X-Spam-Score -2.151
Reply-To Sean Whitton <spwhitton@spwhitton.name>, 1089079@bugs.debian.org
Resent-To debian-bugs-dist@lists.debian.org
Resent-Cc debian-python@lists.debian.org, c.schoenert@t-online.de, Debian Release Team <debian-release@lists.debian.org>
X-Debian-Pr-Message report 1089079
X-Debian-Pr-Package release.debian.org
X-Debian-Pr-Keywords bookworm
Feedback-ID 20115:3760:null:purelymail
X-Pm-Original-To submit@bugs.debian.org
MIME-Version 1.0
Content-Type multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="ZEAsCNKUyYsdodCA"
Content-Disposition inline
X-Reportbug-Version 12.0.0
X-Debian-Message from BTS
X-Mailing-List <debian-bugs-dist@lists.debian.org> archive/latest/1871643
List-ID <debian-bugs-dist.lists.debian.org>
List-URL <https://lists.debian.org/debian-bugs-dist/>
Approved robomod@news.nic.it
Lines 546
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Thu, 5 Dec 2024 11:57:48 +0800
X-Original-Message-ID <Z1EkvLhu4-qLdkca@melete.silentflame.com>
Xref csiph.com linux.debian.bugs.dist:1222779 linux.debian.maint.python:16527 linux.debian.devel.release:128417

Cross-posted to 3 groups.

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian.org@packages.debian.org
Usertags: pu
X-Debbugs-Cc: debian-python@lists.debian.org, c.schoenert@t-online.de
Control: affects -1 + src:python-werkzeug

Dear release team,

Fix three DoS CVEs.  Straightforward backports of upstream's commits, all of
which are already in unstable.

Upstream's test suite passes so I believe that no ordinary functionality is
impacted, although, upstream did not provide new tests to verify the fixes.

The changes regarding trusted hosts is only for the debugger, so wouldn't
inadvertedly impact anyone's production usage.

I have not uploaded, but pushed to salsa:python-team/packages/python-werkzeug#debian/bookworm.

Thanks.

-- 
Sean Whitton

Back to linux.debian.maint.python | Previous | Next | Find similar | Unroll thread


Thread

Bug#1089079: bookworm-pu: package python-werkzeug/2.2.2-3+deb12u1 Sean Whitton <spwhitton@spwhitton.name> - 2024-12-05 05:10 +0100

csiph-web