Commits on Source (2)
-
Ola Lundqvist authored
Concluded that the mentioned code is in place for jessie but the vulnerability is minor. It is possible to execute arbitrary arithmetic expression but not arbitrary expression.
-
Ola Lundqvist authored
CVE-2019-19918 and CVE-2019-19917 are marked as no-dsa for Buster and Stretch. No reason to treat Jessie differently. Since there are just two CVEs for lout the package is also removed from dla-needed.txt.