[ubuntu/noble-security] adsys 0.14.3~24.04ubuntu0.1 (Accepted)

Rodrigo Figueiredo Zaiden rodrigo.zaiden at canonical.com
Thu Jan 9 15:17:28 UTC 2025


adsys (0.14.3~24.04ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: Denial of service in parse function.
    - Use strings.EqualFold instead of direct comparison and
      strings.ToLower in .../html/doctype.go, .../html/foreign.go, and
      .../html/parse.go. Based on
      https://go.googlesource.com/net/+/8e66b04771e35c4e4125e8c60334b34e2423effb
      upstream patch.
    - CVE-2024-45338

adsys (0.14.3~24.04) noble; urgency=medium

  [Davi Henrique]
  * Ignore casing when fetching Registry.pol (LP: #2080390)
  * Add configurable timeout for listing GPOs (LP: #2081966)

  [Felipe Alencastro]
  * Add support for DCONF usb settings (LP: #2081968)

Date: 2025-01-07 18:44:10.199149+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Signed-By: Rodrigo Figueiredo Zaiden <rodrigo.zaiden at canonical.com>
https://launchpad.net/ubuntu/+source/adsys/0.14.3~24.04ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list