diff --git a/.gitmodules b/.gitmodules index ea0d1bf..e81a36b 100644 --- a/.gitmodules +++ b/.gitmodules @@ -1944,7 +1944,7 @@ url = ../../pool/openjade [submodule "openjpeg2"] path = openjpeg2 - url = ../../pool/openjpeg2 + url = ../../ALP-pool/openjpeg2 [submodule "openldap2"] path = openldap2 url = ../../ALP-pool/openldap2 diff --git a/openjpeg2 b/openjpeg2 index e1f827a..380edec 160000 --- a/openjpeg2 +++ b/openjpeg2 @@ -1 +1 @@ -Subproject commit e1f827a6581b29f52a5eff4032c0b8202590b404 +Subproject commit 380edec9d00b05913125a42d5e4918bd89e76608 diff --git a/patchinfo.20241205104818940237.90520734224241/_patchinfo b/patchinfo.20241205104818940237.90520734224241/_patchinfo new file mode 100644 index 0000000..8718afe --- /dev/null +++ b/patchinfo.20241205104818940237.90520734224241/_patchinfo @@ -0,0 +1,19 @@ + + + VUL-0: CVE-2024-49769: python-waitress: incorrect connection clean up leads to a busy-loop and resource exhaustion + VUL-0: CVE-2024-49768: python-waitress: request processing race condition in HTTP pipelining with invalid first request when lookahead is enabled + + + nkrapp + important + security + Security update for python-waitress + This update for python-waitress fixes the following issues: + +- CVE-2024-49768: Incorrect connection clean up leads to a busy-loop and resource exhaustion (bsc#1232556). +- CVE-2024-49769: Request processing race condition in HTTP pipelining with invalid first request when lookahead is enabled (bsc#1232554). + + python-waitress + python-waitress:doc + +