Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1196453

Bug#1070478: bookworm-pu: package tryton-server/tryton-server_6.0.29-2+deb12u2

From Mathias Behrle <mbehrle@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.devel.release
Subject Bug#1070478: bookworm-pu: package tryton-server/tryton-server_6.0.29-2+deb12u2
Date 2024-05-06 10:40 +0200
Message-ID <IB237-brF2-1@gated-at.bofh.it> (permalink)
Organization .

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Package: release.debian.org
Severity: normal
Tags: bookworm
X-Debbugs-Cc: tryton-server@packages.debian.org
Control: affects -1 + src:tryton-server
User: release.debian.org@packages.debian.org
Usertags: pu

[ Reason ]
Backport the patch to fix the vulnerabilty to zip bomb
attacks via decoded gzip content from unauthenticated users.
https://discuss.tryton.org/t/security-release-for-issue-13142/7196

In coordination with the security team it was classified as NO-DSA and
rather be applicable via bookworm-pu.

[ Impact ]
Without the patch any unauthenticated users could perform zimp bomb
attacks against tryton-server.

[ Tests ]
The test suite completes without errors. The patch is now publicly
available and in use since 20 days.

[ Risks ]
The patch has minimal complexity and is from the upstream author
who is generally very knowledgable about his code.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
The upstream commit was added as a patch that allows gzip
compressed content only for authenticated users.

01_avoid_call_to_pypi.patch was refreshed to apply cleanly with no
further changes.

[ Other info ]
This patch requires also a patch for tryton-client in a separate upload
to prevent a regression of tryton-client when it tries to send gzipped
content without authentication.



-- 

    Mathias Behrle
    PGP/GnuPG key availabable from any keyserver, ID: 0xD6D09BE48405BBF6
    AC29 7E5C 46B9 D0B6 1C71  7681 D6D0 9BE4 8405 BBF6

Back to linux.debian.bugs.dist | Previous | Next | Find similar | Unroll thread


Thread

Bug#1070478: bookworm-pu: package tryton-server/tryton-server_6.0.29-2+deb12u2 Mathias Behrle <mbehrle@debian.org> - 2024-05-06 10:40 +0200

csiph-web