Hi,
After fixing CVE-2025-27773 (#1100595) for LTS I was taking a look
to tackle unstable as well (as step toward fixing stable9.
While doing this I noticed that the changelog entry for 1.19.7-1+deb12u1
only mentions CVE-2024-52596 but not CVE-2024-52806, and there is also
only a patch named CVE-2024-52596 [1] but no sign of a fix for CVE-2024- 52806, so I believe the latter has not been fixed with 1.19.7-1+deb12u1, despite security tracker saying so.
Possibly I've missed something, so I'd appreciate if someone could
verify my findings.
[1] the patch content matches the upstream patch mentioned in the
security tracker,
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (0 / 16) |
Uptime: | 166:44:06 |
Calls: | 10,385 |
Calls today: | 2 |
Files: | 14,057 |
Messages: | 6,416,529 |