Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (2)
CVE-2019-5420,rails: Jessie is not affected
· ba732fcd
Markus Koschany
authored
Mar 30, 2019
The vulnerable code is not present in the 4.x branch of rails.
ba732fcd
Reserve DLA-1739-1 for rails
· 9126ab66
Markus Koschany
authored
Mar 30, 2019
9126ab66
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
9126ab66
...
...
@@ -13282,6 +13282,7 @@ CVE-2019-5421
RESERVED
CVE-2019-5420 (A remote code execution vulnerability in development mode Rails <5. ...)
- rails 2:5.2.2.1+dfsg-1 (bug #924521)
[jessie] - <not-affected> (vulnerable code is not present in 4.x)
NOTE: https://www.openwall.com/lists/oss-security/2019/03/13/3
CVE-2019-5419 (There is a possible denial of service vulnerability in Action View (Ra ...)
- rails 2:5.2.2.1+dfsg-1 (bug #924520)
data/DLA/list
View file @
9126ab66
[30 Mar 2019] DLA-1739-1 rails - security update
{CVE-2019-5418 CVE-2019-5419}
[jessie] - rails 2:4.1.8-1+deb8u5
[30 Mar 2019] DLA-1738-1 gpsd - security update
{CVE-2018-17937}
[jessie] - gpsd 3.11-3+deb8u1
...
...
data/dla-needed.txt
View file @
9126ab66
...
...
@@ -89,8 +89,6 @@ python3.4 (Roberto C. Sánchez)
qemu
NOTE: CVE-2018-19665: wait for final patch
--
rails (Markus Koschany)
--
sox
NOTE: 20190305: CVE-2019-835{4,5,6,7} no upstream patch yet, might take some time.
NOTE: Check again later. - hle
...
...