Discussion:
Bug#1088709: bookworm-pu: package redis/5:7.0.15-1~deb12u2
(too old to reply)
Adrian Bunk
2024-11-29 21:00:01 UTC
Permalink
Package: release.debian.org
Severity: normal
Tags: bookworm moreinfo
User: ***@packages.debian.org
Usertags: pu
X-Debbugs-Cc: Chris Lamb <***@debian.org>, ***@debian.org

* CVE-2024-31227: DoS with malformed ACL selectors
* CVE-2024-31228: unbounded pattern matching DoS
* CVE-2024-31449: Lua bit library stack overflow

Tagged moreinfo, as question to the security team whether they want
this in -pu or as DSA.
Salvatore Bonaccorso
2024-11-30 18:20:01 UTC
Permalink
Control: tags -1 - moreinfo

Hi Adrian,
Post by Adrian Bunk
Package: release.debian.org
Severity: normal
Tags: bookworm moreinfo
Usertags: pu
* CVE-2024-31227: DoS with malformed ACL selectors
* CVE-2024-31228: unbounded pattern matching DoS
* CVE-2024-31449: Lua bit library stack overflow
Tagged moreinfo, as question to the security team whether they want
this in -pu or as DSA.
Thanks for the question. Moritz did earlier today mark the 3 CVEs as
no-dsa, and releasing the update via the next point release is
sufficient.

Regards,
Salvatore
Debian Bug Tracking System
2024-11-30 18:20:01 UTC
Permalink
Post by Salvatore Bonaccorso
tags -1 - moreinfo
Bug #1088709 [release.debian.org] bookworm-pu: package redis/5:7.0.15-1~deb12u2
Removed tag(s) moreinfo.
--
1088709: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1088709
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Jonathan Wiltshire
2024-12-06 14:00:02 UTC
Permalink
package release.debian.org
tags 1088709 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==============

Package: redis
Version: 7.0.15-1~deb12u2

Explanation: fix denial of service with malform ACL selectors [CVE-2024-31227]; fix denial of service through unbound pattern matching [CVE-2024-31228]; fix stack overflow [CVE-202431449]
Debian Bug Tracking System
2025-01-11 11:20:04 UTC
Permalink
Your message dated Sat, 11 Jan 2025 11:03:09 +0000
with message-id <E1tWZGn-009jbO-***@coccia.debian.org>
and subject line Close 1088709
has caused the Debian Bug report #1088709,
regarding bookworm-pu: package redis/5:7.0.15-1~deb12u2
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ***@bugs.debian.org
immediately.)
--
1088709: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1088709
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Loading...