Skip to content
Commit eee09f95 authored by Markus Koschany's avatar Markus Koschany
Browse files

CVE-2019-9917,znc: Change status from not-affected to no-dsa

After discussion with upstream clarify that the version of znc in Jessie is
affected by CVE-2019-9917. Although users cannot set the encoding because this
feature does not exist, the modpython module is still vulnerable when parsing
non-UTF-8 strings. The workaround is to disable modpython or to deinstall the
znc-python package. Backporting the encoding feature to Jessie is probably not
worth the time. We could consider to upgrade to a newer version instead should another
serious issue be discovered.
parent 0127b330
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment