Description: "Autobahn before 20.12.3 allows redirect header injection."
Please bump to 20.12.3, thanks!
IIRC the bump is non-trivial and requires changes to the test phase.
(In reply to Michał Górny from comment #2) > IIRC the bump is non-trivial and requires changes to the test phase. Unfortunate. Ping dolsen.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2581b9ad72da062585285a9977f942954995219c commit 2581b9ad72da062585285a9977f942954995219c Author: Brian Dolbec <dolsen@gentoo.org> AuthorDate: 2021-01-17 18:44:32 +0000 Commit: Brian Dolbec <dolsen@gentoo.org> CommitDate: 2021-01-17 18:45:31 +0000 dev-python/autobahn: Version bump to 20.12.3, adds python-3.9 (CVE-2020-35678) Bug: https://bugs.gentoo.org/761840 Closes: https://bugs.gentoo.org/761439 Package-Manager: Portage-3.0.10, Repoman-3.0.2 Signed-off-by: Brian Dolbec <dolsen@gentoo.org> dev-python/autobahn/Manifest | 1 + dev-python/autobahn/autobahn-20.12.3.ebuild | 105 ++++++++++++++++++++++++++++ 2 files changed, 106 insertions(+)
Please proceed with stabilization when ready.
Sanity check failed: > dev-python/autobahn-20.12.3 > rdepend amd64 dev profile default/linux/amd64/17.0/no-multilib/prefix/kernel-3.2+ (4 total) > >=dev-python/snappy-0.5[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)] > >=dev-python/txaio-20.4.1[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)] > rdepend amd64 stable profile default/linux/amd64/17.1 (23 total) > >=dev-python/snappy-0.5[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)] > >=dev-python/txaio-20.4.1[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)] > rdepend arm stable profile default/linux/arm/17.0 (12 total) > >=dev-python/cbor2-5.1.0[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)] > >=dev-python/snappy-0.5[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)] > >=dev-python/txaio-20.4.1[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)] > rdepend arm dev profile default/linux/arm/17.0/armv4 (35 total) > >=dev-python/cbor2-5.1.0[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)] > >=dev-python/snappy-0.5[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)] > >=dev-python/txaio-20.4.1[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)]
Unable to check for sanity: > dependent bug #765901 is missing keywords
All sanity-check issues have been resolved
amd64 stable
x86 stable
Sanity check failed: > dev-python/autobahn-20.12.3 > rdepend arm stable profile default/linux/arm/17.0 (1 total) > >=dev-python/cbor2-5.1.0[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)] > rdepend arm dev profile default/linux/arm/17.0/armv4 (35 total) > >=dev-python/cbor2-5.1.0[-python_single_target_python3_7(-),-python_single_target_python3_8(-),-python_single_target_python3_9(-),python_targets_python3_7(-),python_targets_python3_8(-),python_targets_python3_9(-)]
arm done
arm64 done all arches done
Unable to check for sanity: > no match for package: dev-python/autobahn-20.12.3