| Summary: | jupyter-nbconvert new security issue CVE-2021-32862 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | David GEIGER <geiger.david68210> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | nicolas.salguero |
| Version: | 8 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | jupyter-nbconvert-5.6.1-2.mga8.src.rpm | CVE: | |
| Status comment: | Fixed upstream in 6.5.1 | ||
|
Description
David Walser
2023-06-16 00:13:35 CEST
Oops, we already have 5.6.1, but are probably missing the regression fixes. Severity:
critical =>
normal I don't found any 5.6.2 nor 5.6.3 release! CC:
(none) =>
geiger.david68210 That's odd. From Debian, it looks like it just needs these two commits: https://github.com/jupyter/nbconvert/commit/c289e0a61660e612920397799169ed2c5ed35516 https://github.com/jupyter/nbconvert/commit/1652aa73b0f4900af97c0f1ac08e9573e00155bd The releases are here: https://github.com/jupyter/nbconvert/releases/tag/6.5.2 https://github.com/jupyter/nbconvert/releases/tag/6.5.3 And now I just noticed I went a bit dyslexic here. We do have a security bug. Which is fixed upstream in 6.5.1: https://github.com/jupyter/nbconvert/releases/tag/6.5.1 Summary:
jupyter-nbconvert regressions fixed upstream in 5.6.3 =>
jupyter-nbconvert new security issue CVE-2021-32862 (In reply to David Walser from comment #3) > And now I just noticed I went a bit dyslexic here I imagine in saying "5.6.x" in lieu of "6.5.x". Explains comment 2. In reply to David Walser from comment #1) > Oops, we already have 5.6.1, but are probably missing the regression fixes. Over 3 years old... David, this is yet another fix you have taken on board. Given that various packagers have done the most recent commits, I would otherwise have assigned this to pkg-bugs. Do that if you feel (justifiably) that you have too much on your plate. Assignee:
bugsquad =>
geiger.david68210 Mageia 8 EOL Resolution:
(none) =>
OLD |