Hi,
I am jq maintainer, and right now CVE-2023-49355 is listed in security
tracker [0]. However, this CVE is equal to CVE-2023-50246 according to
upstream [1], which has been fixed in 1.7.1-1 [2].
In this case, how should I handle CVE-2023-49355?
[0]
https://security-tracker.debian.org/tracker/source-package/jq
[1]
https://github.com/jqlang/jq/issues/2986
[2]
https://bugs.debian.org/1058763
--
ChangZhuo Chen (陳昌倬) czchen@{czchen,debian}.org
Key fingerprint = BA04 346D C2E1 FE63 C790 8793 CC65 B0CD EC27 5D5B
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEugQ0bcLh/mPHkIeTzGWwzewnXVsFAmV9eKEACgkQzGWwzewn XVuOKw/9H9uMKuMRbsrFoKj/fZyAzp9FDNd0RTlbQGii0kSgf+IB9YDrhUASibZI PV2EVk6r+L1hZsDBuU9GfbhVhD1UfFq8zXfmvB4thTOi2ahqGGP33TYns6bkaK0G In4N5+SVem6/5rGA3cYLAlnf5Tr2Ooazh2OQGc5hdD/IjIIkl87bSwtJTQQ+CS3s pTQgCRIQPwPVpDPlaSrojGLMmhGzHKZzLWhKxfCsVWVua4vKTwc3QZ4urbLx8bk6 prvspzuLX1s9jvSitXHYb1+cnylKNoRcrriKjtotnR5P0hjNDl1GPyztwpV6latw s0EC1p5MlM9xmLQbjfTIVKk1Q346sEb8saPs8XLSPdxYNo7Y+wtrtyBQt9ZeG1Os vcUsa2EOadyBPe8KOuCtRi/NoI5onxu+SW6G4gieeAQmiJt7GfsMAcYARst9zWtM lEpzTJuZXcOT6ipfcJNhW+aq2QIsOJnnFEO1D6N96xvqVka3SUCSx1Qw8ufzejxS di5VD1E4bS98sFtpq6sIXeDnNzvBq96lMQmaANdGndrkV1IQprKEJbt6ktYs+U9d h3bVtoIkjicbS2gxN2eFe9dWgk5BdTt7zPqwqQ6dcQt7NCyPg20KCYy6TBhp++Ai Eixcbau+CEanIfQlsdfrJAppRtjHBOKWv2NNtIDFM8EEZZRFUVQ=
=jcSd
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: fsxN