[Git][security-tracker-team/security-tracker][master] Reserve DLA-1569-1 for libdatetime-timezone-perl
Emilio Pozuelo Monfort
pochu at debian.org
Wed Nov 7 17:29:14 GMT 2018
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9d7eb06a by Emilio Pozuelo Monfort at 2018-11-07T17:29:02Z
Reserve DLA-1569-1 for libdatetime-timezone-perl
- - - - -
2 changed files:
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,5 @@
+[07 Nov 2018] DLA-1569-1 libdatetime-timezone-perl - new upstream version
+ [jessie] - libdatetime-timezone-perl 1:1.75-2+2018g
[06 Nov 2018] DLA-1568-1 curl - security update
{CVE-2016-7141 CVE-2016-7167 CVE-2016-9586 CVE-2018-16839 CVE-2018-16842}
[jessie] - curl 7.38.0-4+deb8u13
=====================================
data/dla-needed.txt
=====================================
@@ -49,8 +49,6 @@ libav (Hugo Lefeuvre)
NOTE: 20180529: Help is welcome, feel free to mail Hugo. Still up-to-date. Help needed for CVE triage and patch development.
NOTE: 20180529: Just contacted some of the CVE reporters to ask for the reproducers, CC-ed team ML.
--
-libdatetime-timezone-perl (Emilio Pozuelo)
---
liblivemedia (Hugo Lefeuvre)
NOTE: CVE entry says remote: "no", but it looks like a pretty exploitable remote vulnerability
NOTE: (remote code execution)... CVE is very well documented so I think this is worth a patch
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/9d7eb06a927a38fa255d414fc5df6c10eb7f52c4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/9d7eb06a927a38fa255d414fc5df6c10eb7f52c4
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181107/7f23a22d/attachment.html>
More information about the debian-security-tracker-commits
mailing list