CVE-2019-17638

NameCVE-2019-17638
DescriptionIn Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in ca ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
jetty9 (PTS)bullseye9.4.50-4+deb11u2fixed
bullseye (security)9.4.57-0+deb11u3fixed
bookworm, bookworm (security)9.4.57-1.1~deb12u1fixed
trixie (security), trixie9.4.57-1.1~deb13u1fixed
forky, sid9.4.58-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
jetty9sourcestretch(not affected)
jetty9sourcebuster(not affected)
jetty9source(unstable)9.4.31-1

Notes

[buster] - jetty9 <not-affected> (vulnerable code was introduced in 9.4.27)
[stretch] - jetty9 <not-affected> (vulnerable code was introduced in 9.4.27)
https://bugs.eclipse.org/bugs/show_bug.cgi?id=564984
https://github.com/eclipse/jetty.project/issues/4936

Search for package or bug name: Reporting problems