- -------------------------------------------------------------------------
Debian Security Advisory DSA-4206-2                   security@debian.org
https://www.debian.org/security/                     Salvatore Bonaccorso
May 26, 2018                          https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : gitlab
Debian Bug     : 900066

The gitlab security update announced as DSA-4206-1 caused regressions
when creating merge requests (returning 500 Internal Server Errors) due
to an issue in the patch to address CVE-2017-0920. Updated packages are
now available to correct this issue.

For the stable distribution (stretch), this problem has been fixed in
version 8.13.11+dfsg1-8+deb9u3.

We recommend that you upgrade your gitlab packages.

For the detailed security status of gitlab please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/source-package/gitlab

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Debian: DSA-4206-2: gitlab regression update

May 26, 2018
The gitlab security update announced as DSA-4206-1 caused regressions when creating merge requests (returning 500 Internal Server Errors) due to an issue in the patch to address CV...

Summary

For the stable distribution (stretch), this problem has been fixed in
version 8.13.11+dfsg1-8+deb9u3.

We recommend that you upgrade your gitlab packages.

For the detailed security status of gitlab please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/source-package/gitlab

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Severity
The gitlab security update announced as DSA-4206-1 caused regressions
when creating merge requests (returning 500 Internal Server Errors) due
to an issue in the patch to address CVE-2017-0920. Updated packages are
now available to correct this issue.

Related News