|
|
Subscribe / Log in / New account

Debian alert DLA-2555-1 (netty)

From:  Chris Lamb <lamby@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2555-1] netty security update
Date:  Thu, 11 Feb 2021 08:02:37 -0500
Message-ID:   <161304850829.2751747.6953127498344916803@tinycat.chris-lamb.co.uk>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2555-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb February 11, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : netty Version : 1:4.1.7-2+deb9u3 CVE ID : CVE-2021-21290 It was discovered that there was an insecure temporary file issue that could have lead to disclosure of arbitrary local files. For Debian 9 "Stretch", this problem has been fixed in version 1:4.1.7-2+deb9u3. We recommend that you upgrade your netty packages. For the detailed security status of netty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/netty Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmAlKrgACgkQHpU+J9Qx Hlhw2xAAnggPxxpcDY4G61KIxFDf03hfW3P4PL/jxktLDFUmRRTrLHdNSBjhMcDn OfQtKlYE6asKadXPmas1wEDhFADoUytyWA2zZcUFcTi1eks99Cce9835vjzI0JpB CiV+z+0fJFOWgFrjUMoyt6yKNKyTZmZKCal6wHbirbCheQtzR1dVUz9XLiyw8Ve6 TBg/dk1USQATHt264gxgVnTQwWDoMZNZtA0bEjGiRRBm57KjbiMCvfg1kKgSu35R IYStA0DtjaiS7V0dLYSO4QTofiLNFUCb0xnr1HtqiSA3WikmO2sWisTjk1Hbk0q0 asayghwu4jQN0DFwzLp655COK1p5NcnkYHEb3K+tErTU9OQyKKbCf52751R5vMms ZucUq7PL8wDSHgxWfYzY8nyvQC4jQ1l4gj270V7uISQRMjwUUMrdVO/7nzNTbCre D03HiIHTfIHiTBCdp8+RlMGDWdeA+MQVnS4cXdP1sX0GpwIyzE6t82UDCk4xOsEb /wgr0Bc5dzxTpcaqTavio57c1tLvsB84BPkm5m2hpfwpKWd33AAm0eyUCjZNpBug WWARmwfdVEwwEzWS8kX8WIAcCMGKKtfWDfnVobbNV76OKQdo0gR6LUtZZHQAMhbm keKbXR4jrNJsaDScc+Ya2lYg/B0QzYsZaWWjDzcbnI7lvqCp72g= =oCJA -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds