From 110d9012cf29fee32b1d5f8fa0445eb9c6d9f1ae Mon Sep 17 00:00:00 2001 From: Thorsten Alteholz Date: Sun, 10 May 2020 11:51:27 +0200 Subject: DLA 2197 1 --- english/lts/security/2020/dla-2197.data | 10 ++++++++++ english/lts/security/2020/dla-2197.wml | 21 +++++++++++++++++++++ 2 files changed, 31 insertions(+) create mode 100644 english/lts/security/2020/dla-2197.data create mode 100644 english/lts/security/2020/dla-2197.wml (limited to 'english') diff --git a/english/lts/security/2020/dla-2197.data b/english/lts/security/2020/dla-2197.data new file mode 100644 index 00000000000..9ddb8758a7c --- /dev/null +++ b/english/lts/security/2020/dla-2197.data @@ -0,0 +1,10 @@ +DLA-2197-1 miniupnpc +2020-4-30 +CVE-2017-8798 +miniupnpc +yes +yes +no + +#use wml::debian::security + diff --git a/english/lts/security/2020/dla-2197.wml b/english/lts/security/2020/dla-2197.wml new file mode 100644 index 00000000000..e11e6b9045a --- /dev/null +++ b/english/lts/security/2020/dla-2197.wml @@ -0,0 +1,21 @@ +LTS security update + + +

It was discovered that there was a integer signedness error in the +miniupnpc UPnP client that could allow remote attackers to cause a denial +of service attack.

+ + +

For Debian 8 Jessie, this problem has been fixed in +version 1.9.20140610-2+deb8u2.

+ +

We recommend that you upgrade your miniupnpc packages.

+ +

Further information about Debian LTS security advisories, how to apply +these updates to your system and frequently asked questions can be +found at: https://wiki.debian.org/LTS

+
+ +# do not modify the following line +#include "$(ENGLISHDIR)/lts/security/2020/dla-2197.data" +# $Id: $ -- cgit v1.2.3