[Bug 1064980] VUL-0: CVE-2016-10517: redis: POST and Host: strings lack a check that allows "Cross Protocol Scripting"
http://bugzilla.suse.com/show_bug.cgi?id=1064980 http://bugzilla.suse.com/show_bug.cgi?id=1064980#c2 Martin Pluskal <mpluskal@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |IN_PROGRESS --- Comment #2 from Martin Pluskal <mpluskal@suse.com> --- (In reply to Andreas Stieger from comment #1)
Martin did the 3.2.7 bump. Could you add the CVE to the changelog and trigger the updates?
Submitted for Factory, for Leap and Backports each has different version, but upon reviewing changes I would probably go for version bump to Factory version for Leap and Backports - most of changes are bugfixes anyways. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com