[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2019-12779/libqb: jessie end-of-life

Roberto C. Sánchez roberto at debian.org
Mon Nov 18 02:32:00 GMT 2019



Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker


Commits:
67573539 by Roberto C. Sánchez at 2019-11-18T02:30:55Z
CVE-2019-12779/libqb: jessie end-of-life

- - - - -
b55d19b5 by Roberto C. Sánchez at 2019-11-18T02:31:37Z
LTS/libqb: remove from dla-needed.txt as it is now EOL

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -21647,6 +21647,7 @@ CVE-2019-5439 (A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash w
 	NOTE: http://www.jbkempf.com/blog/post/2019/VLC-3.0.7-and-security
 CVE-2019-12779 (libqb before 1.0.5 allows local users to overwrite arbitrary files via ...)
 	- libqb 1.0.4-1 (unimportant; bug #927159)
+	[jessie] - libqb <end-of-life> (https://salsa.debian.org/debian/debian-security-support/commit/ba638006d397eda2cc094761ed7a7bfdca9e534b)
 	NOTE: https://github.com/ClusterLabs/libqb/issues/338
 	NOTE: https://github.com/ClusterLabs/libqb/commit/6a4067c1d1764d93d255eccecfd8bf9f43cb0b4d
 	NOTE: Regression fix: https://github.com/ClusterLabs/libqb/pull/349


=====================================
data/dla-needed.txt
=====================================
@@ -71,13 +71,6 @@ libmatio (Adrian Bunk)
   NOTE: 20190428: older changes seem to also be required for them
   NOTE: 20191111: work is ongoing
 --
-libqb (Roberto C. Sánchez)
-  NOTE: 20190616: Upstream patch does not apply at all, but it appears that
-  NOTE: 20190616: package is still vulnerable in ipc_posix_mq.c etc. or
-  NOTE: 20190616: wherever it uses c->pid w/NAME_MAX. (lamby)
-  NOTE: 20190619: See https://lists.debian.org/debian-lts/2019/06/msg00015.html
-  NOTE: 20191111: Made an attempt at backporting relevant commits; requested review by upstream. (roberto)
---
 libvpx (Dylan Aïssi)
 --
 linux (Ben Hutchings)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/d989a77d1fe360ab0be6183b331fc3384f19db7d...b55d19b5bbb358f7ff4b090e0a1640e40f371af6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/d989a77d1fe360ab0be6183b331fc3384f19db7d...b55d19b5bbb358f7ff4b090e0a1640e40f371af6
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191118/fbb4affe/attachment.html>


More information about the debian-security-tracker-commits mailing list