[Git][security-tracker-team/security-tracker][master] Reserve DLA-1675-1 for python-gnupg

Markus Koschany apo at debian.org
Thu Feb 14 13:28:40 GMT 2019


Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7056225f by Markus Koschany at 2019-02-14T13:28:33Z
Reserve DLA-1675-1 for python-gnupg

- - - - -


2 changed files:

- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[14 Feb 2019] DLA-1675-1 python-gnupg - security update
+	{CVE-2019-6690}
+	[jessie] - python-gnupg 0.3.6-1+deb8u1
 [12 Feb 2019] DLA-1674-1 php5 - security update
 	{CVE-2018-1000888}
 	[jessie] - php5 5.6.39+dfsg-0+deb8u2


=====================================
data/dla-needed.txt
=====================================
@@ -107,11 +107,6 @@ phpmyadmin
 polarssl
   NOTE: 20121207: Not 100% sure if vulnerable. Upstream would prefer us to move to latest version, etc. (!). (lamby)
 --
-python-gnupg (Markus Koschany)
-  NOTE: 20190201: Bug can be reproduced on Buster/Sid with Jessie's version of
-  NOTE: python-gnupg. Reproducer will not work in Jessie environment because of
-  NOTE: older python version. (apo)
---
 qemu (Hugo Lefeuvre)
   NOTE: CVE-2018-19665: working on a highly trimmed down version of upstream patch
   NOTE: CVE-2018-19665: also, current patch will not be merged by upstream, wait for updated version



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/7056225f202c97cd73d238342efc15c0fdf7e73a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/7056225f202c97cd73d238342efc15c0fdf7e73a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190214/7b7456d2/attachment.html>


More information about the debian-security-tracker-commits mailing list