[Git][security-tracker-team/security-tracker][master] drop two no-dsa for python, included in upcoming DSAs
Moritz Muehlenhoff
jmm at debian.org
Thu Sep 27 18:34:42 BST 2018
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e7f76f32 by Moritz Muehlenhoff at 2018-09-27T17:33:43Z
drop two no-dsa for python, included in upcoming DSAs
one non-issue
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -29306,12 +29306,8 @@ CVE-2018-1000030 (Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well
- python3.5 <not-affected> (Reading ahead of file objects implemented differently)
- python3.4 <not-affected> (Reading ahead of file objects implemented differently)
- python3.2 <not-affected> (Reading ahead of file objects implemented differently)
- - python2.7 2.7.14-5
- [stretch] - python2.7 <no-dsa> (Minor issue)
- [jessie] - python2.7 <no-dsa> (Minor issue)
- [wheezy] - python2.7 <no-dsa> (Minor issue)
- - python2.6 <removed>
- [wheezy] - python2.6 <no-dsa> (Minor issue)
+ - python2.7 2.7.14-5 (unimportant)
+ - python2.6 <removed> (unimportant)
NOTE: Original report: https://bugs.python.org/issue31530
NOTE: https://bugs.python.org/file47157/0001-stop-crashes-when-iterating-over-a-file-on-multiple-.patch
NOTE: which was followed by a pull request to fix the issue:
@@ -29323,6 +29319,7 @@ CVE-2018-1000030 (Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well
NOTE: https://bugs.python.org/msg309265
NOTE: where the 6401e56 commit was mostly reverted again.
NOTE: Needed: https://github.com/python/cpython/commit/dbf52e02f18dac6f5f0a64f78932f3dc6efc056b
+ NOTE: No practical security impact, why DWF assigned a CVE ID is hard to tell
CVE-2018-1000029 (mcholste Enterprise Log Search and Archive (ELSA) version revision ...)
NOT-FOR-US: mcholste Enterprise Log Search and Archive
CVE-2018-1000026 (Linux Linux kernel version at least v4.8 onwards, probably well before ...)
@@ -44858,12 +44855,10 @@ CVE-2018-1061 (python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.
- python3.7 3.7.0~b3-1 (low)
- python3.6 3.6.5~rc1-1 (low)
- python3.5 3.5.6-1 (low)
- [stretch] - python3.5 <no-dsa> (Minor issue)
- python3.4 <removed> (low)
- python3.2 <removed> (low)
[wheezy] - python3.2 <no-dsa> (Minor issue)
- python2.7 2.7.14-7 (low)
- [stretch] - python2.7 <no-dsa> (Minor issue)
[wheezy] - python2.7 <no-dsa> (Minor issue)
- python2.6 <removed> (low)
[wheezy] - python2.6 <no-dsa> (Minor issue)
@@ -44879,12 +44874,10 @@ CVE-2018-1060 (python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.
- python3.7 3.7.0~b3-1 (low)
- python3.6 3.6.5~rc1-1 (low)
- python3.5 3.5.6-1 (low)
- [stretch] - python3.5 <no-dsa> (Minor issue)
- python3.4 <removed> (low)
- python3.2 <removed> (low)
[wheezy] - python3.2 <no-dsa> (Minor issue)
- python2.7 2.7.14-7 (low)
- [stretch] - python2.7 <no-dsa> (Minor issue)
[wheezy] - python2.7 <no-dsa> (Minor issue)
- python2.6 <removed> (low)
[wheezy] - python2.6 <no-dsa> (Minor issue)
=====================================
data/dsa-needed.txt
=====================================
@@ -66,6 +66,10 @@ passenger
php7.0
wait until more severe issues have come up
--
+python2.7 (jmm)
+--
+python3.5 (jmm)
+--
smarty3
--
spamassassin
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e7f76f325f00fbea84d9e0cb9f3e60d1c47f8c2d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e7f76f325f00fbea84d9e0cb9f3e60d1c47f8c2d
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180927/ca4b7570/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list