[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2019-12779/libqb: jessie end-of-life
Roberto C. Sánchez
roberto at debian.org
Mon Nov 18 02:32:00 GMT 2019
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker
Commits:
67573539 by Roberto C. Sánchez at 2019-11-18T02:30:55Z
CVE-2019-12779/libqb: jessie end-of-life
- - - - -
b55d19b5 by Roberto C. Sánchez at 2019-11-18T02:31:37Z
LTS/libqb: remove from dla-needed.txt as it is now EOL
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -21647,6 +21647,7 @@ CVE-2019-5439 (A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash w
NOTE: http://www.jbkempf.com/blog/post/2019/VLC-3.0.7-and-security
CVE-2019-12779 (libqb before 1.0.5 allows local users to overwrite arbitrary files via ...)
- libqb 1.0.4-1 (unimportant; bug #927159)
+ [jessie] - libqb <end-of-life> (https://salsa.debian.org/debian/debian-security-support/commit/ba638006d397eda2cc094761ed7a7bfdca9e534b)
NOTE: https://github.com/ClusterLabs/libqb/issues/338
NOTE: https://github.com/ClusterLabs/libqb/commit/6a4067c1d1764d93d255eccecfd8bf9f43cb0b4d
NOTE: Regression fix: https://github.com/ClusterLabs/libqb/pull/349
=====================================
data/dla-needed.txt
=====================================
@@ -71,13 +71,6 @@ libmatio (Adrian Bunk)
NOTE: 20190428: older changes seem to also be required for them
NOTE: 20191111: work is ongoing
--
-libqb (Roberto C. Sánchez)
- NOTE: 20190616: Upstream patch does not apply at all, but it appears that
- NOTE: 20190616: package is still vulnerable in ipc_posix_mq.c etc. or
- NOTE: 20190616: wherever it uses c->pid w/NAME_MAX. (lamby)
- NOTE: 20190619: See https://lists.debian.org/debian-lts/2019/06/msg00015.html
- NOTE: 20191111: Made an attempt at backporting relevant commits; requested review by upstream. (roberto)
---
libvpx (Dylan Aïssi)
--
linux (Ben Hutchings)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/d989a77d1fe360ab0be6183b331fc3384f19db7d...b55d19b5bbb358f7ff4b090e0a1640e40f371af6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/d989a77d1fe360ab0be6183b331fc3384f19db7d...b55d19b5bbb358f7ff4b090e0a1640e40f371af6
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191118/fbb4affe/attachment.html>
More information about the debian-security-tracker-commits
mailing list