Debian Patches

Status for jose/11-2+deb12u1

Patch Description Author Forwarded Bugs Origin Last update
1711969854.v12-3-g4ee7708.fix-potential-dos-issue-with-p2c-header.patch Fix potential DoS issue with p2c header
Unbounded p2c headers may be used to cause an application that accept
PBES algorithms to spend a lot of resources running PBKDF2 with a very
high number of iterations.

Limit the maximum number of iterations to to 32768.

Fixes: CVE-2023-50967

Signed-off-by: Sergio Correia <scorreia@redhat.com>
no v12-3-g4ee7708 <https://github.com/latchset/jose/commit/v12-3-g4ee7708> 2024-04-01
for-upstream/2021-12-01.replace-usage-of-which.patch Replace usage of which(1) Christoph Biedl <debian.axhn@manchmal.in-ulm.de> yes 2021-12-01
for-upstream/2021-12-01.probe-for-jq.patch Probe for jq Christoph Biedl <debian.axhn@manchmal.in-ulm.de> yes 2021-12-01
for-upstream/2021-12-01.increase-test-timeout.patch Increase timeout values in the test suite Christoph Biedl <debian.axhn@manchmal.in-ulm.de> yes 2021-12-01
debian/2021-11-29.use-asciidoctor-to-build-manpages.patch Use asciidoctor to build the manpages Christoph Biedl <debian.axhn@manchmal.in-ulm.de> no 2021-11-29

All known versions for source package 'jose'

Links