[Secure-testing-commits] r55230 - data

Raphaël Hertzog hertzog at moszumanska.debian.org
Wed Aug 30 12:22:47 UTC 2017


Author: hertzog
Date: 2017-08-30 12:22:46 +0000 (Wed, 30 Aug 2017)
New Revision: 55230

Modified:
   data/dla-needed.txt
Log:
Add db4.7 and db4.8 to dla-needed.txt

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2017-08-30 10:18:50 UTC (rev 55229)
+++ data/dla-needed.txt	2017-08-30 12:22:46 UTC (rev 55230)
@@ -28,8 +28,15 @@
 connman
 --
 db
-  NOTE: 20170813: Not sure vulnerable as some of the DB_CONFIG code is missing in env_open.c, but the reporter wasn't clear that was the approach anyway. (lamby)
+  NOTE: We might want to wait one month like the security team to ensure
+  NOTE: the fix doesn't create regressions.
 --
+db4.7
+  NOTE: see comments on db.
+--
+db4.8
+  NOTE: see comments on db.
+--
 eglibc
   NOTE: 20170510, patch available, however not yet applied upstream.
   NOTE: 20170706: no change upstream, patch disputed.




More information about the Secure-testing-commits mailing list