Re: xymon vulnerabilities in jessie, stretch and buster


> > Anyways, 4.3.29 introduced quite a few regressions[0], we should probably wait
> > for 4.3.30.
> I would neither upload 4.3.29 nor 4.3.30 to Jessie but only the
> minimal patch plus the hostname regex regression patch as I do for
> Stretch and Buster.

Thanks! I have backported your stretch update, currently testing it.

> Also someone needs first to verify that the Xymon upstream version in
> Jessie (IIRC 4.3.17) is actually vulnerable. Upstream didn't specify
> if any version before 4.3.28 is affected, too.

I did not reproduce the issue, but the vulnerable code is present.


