Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1196453 > unrolled thread

Bug#1070478: bookworm-pu: package tryton-server/tryton-server_6.0.29-2+deb12u2

Started byMathias Behrle <mbehrle@debian.org>
First post2024-05-06 10:40 +0200
Last post2024-05-06 10:40 +0200
Articles 1 — 1 participant

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1070478: bookworm-pu: package tryton-server/tryton-server_6.0.29-2+deb12u2 Mathias Behrle <mbehrle@debian.org> - 2024-05-06 10:40 +0200

#1196453 — Bug#1070478: bookworm-pu: package tryton-server/tryton-server_6.0.29-2+deb12u2

FromMathias Behrle <mbehrle@debian.org>
Date2024-05-06 10:40 +0200
SubjectBug#1070478: bookworm-pu: package tryton-server/tryton-server_6.0.29-2+deb12u2
Message-ID<IB237-brF2-1@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Package: release.debian.org
Severity: normal
Tags: bookworm
X-Debbugs-Cc: tryton-server@packages.debian.org
Control: affects -1 + src:tryton-server
User: release.debian.org@packages.debian.org
Usertags: pu

[ Reason ]
Backport the patch to fix the vulnerabilty to zip bomb
attacks via decoded gzip content from unauthenticated users.
https://discuss.tryton.org/t/security-release-for-issue-13142/7196

In coordination with the security team it was classified as NO-DSA and
rather be applicable via bookworm-pu.

[ Impact ]
Without the patch any unauthenticated users could perform zimp bomb
attacks against tryton-server.

[ Tests ]
The test suite completes without errors. The patch is now publicly
available and in use since 20 days.

[ Risks ]
The patch has minimal complexity and is from the upstream author
who is generally very knowledgable about his code.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
The upstream commit was added as a patch that allows gzip
compressed content only for authenticated users.

01_avoid_call_to_pypi.patch was refreshed to apply cleanly with no
further changes.

[ Other info ]
This patch requires also a patch for tryton-client in a separate upload
to prevent a regression of tryton-client when it tries to send gzipped
content without authentication.



-- 

    Mathias Behrle
    PGP/GnuPG key availabable from any keyserver, ID: 0xD6D09BE48405BBF6
    AC29 7E5C 46B9 D0B6 1C71  7681 D6D0 9BE4 8405 BBF6

[toc] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web