CVE-2019-9917,znc: Change status from not-affected to no-dsa
After discussion with upstream clarify that the version of znc in Jessie is affected by CVE-2019-9917. Although users cannot set the encoding because this feature does not exist, the modpython module is still vulnerable when parsing non-UTF-8 strings. The workaround is to disable modpython or to deinstall the znc-python package. Backporting the encoding feature to Jessie is probably not worth the time. We could consider to upgrade to a newer version instead should another serious issue be discovered.
Loading
Please register or sign in to comment