Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1008090

Bug#959763: shadowsocks-libev: Security vulnerabilities in buster

From Salvatore Bonaccorso <carnil@debian.org>
Newsgroups linux.debian.bugs.dist
Subject Bug#959763: shadowsocks-libev: Security vulnerabilities in buster
Date 2020-05-05 06:50 +0200
Message-ID <A2XGN-3R0-5@gated-at.bofh.it> (permalink)
References <A2VF0-2DB-7@gated-at.bofh.it> <A2VF0-2DB-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hi,

On Mon, May 04, 2020 at 09:33:09PM -0500, John Goerzen wrote:
> Package: shadowsocks-libev
> Version: 3.2.5+ds-1
> Severity: normal
> Tags: security
> 
> Per https://github.com/shadowsocks/shadowsocks-libev/blob/master/debian/changelog :
> 
> shadowsocks-libev (3.3.4-1) unstable; urgency=medium
> 
>   * Minor bug fixes. (#2539, #2565, #2566, #2577)
>   * Security bug fixes. (CVE-2019-5163, CVE-2019-5164)
> 
> It would be good to get this version, or at least these patches, into
> buster security updates.

FWIW, those were marked 'no-dsa', but a fix via an upcoming point
release would be great to have.

Regards,
Salvatore

Back to linux.debian.bugs.dist | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

Bug#959763: shadowsocks-libev: Security vulnerabilities in buster John Goerzen <jgoerzen@complete.org> - 2020-05-05 04:40 +0200
  Bug#959763: shadowsocks-libev: Security vulnerabilities in buster Salvatore Bonaccorso <carnil@debian.org> - 2020-05-05 06:50 +0200

csiph-web