[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2019-16910/polarssl: reference patch, request dla
Sylvain Beucler
beuc at debian.org
Wed Oct 2 17:23:01 BST 2019
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
989e21ee by Sylvain Beucler at 2019-10-02T16:13:45Z
CVE-2019-16910/polarssl: reference patch, request dla
- - - - -
3ca8216a by Sylvain Beucler at 2019-10-02T16:13:45Z
dla: add golang
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -382,6 +382,8 @@ CVE-2019-16910 (Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, whe
- mbedtls 2.16.3-1 (bug #941265)
- polarssl <removed>
NOTE: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2019-10
+ NOTE: https://github.com/ARMmbed/mbedtls/commit/298a43a77ec0ed2c19a8c924ddd8571ef3e65dfd (2.7.12)
+ NOTE: https://github.com/ARMmbed/mbedtls/commit/33f66ba6fd234114aa37f0209dac031bb2870a9b (2.16.3)
CVE-2019-16909
RESERVED
CVE-2019-16908
=====================================
data/dla-needed.txt
=====================================
@@ -24,6 +24,8 @@ freeimage
NOTE: https://lists.debian.org/debian-lts/2019/05/msg00079.html
NOTE: 20190707: maintainer is waiting for upstream https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929597
--
+golang
+--
hdf5
NOTE: 20190825: Upstream is aware of currently open issues. Progress is slow,
NOTE: wait for the next HDF5 point release and either do full package upgrade
@@ -117,6 +119,8 @@ openjpeg2 (Hugo Lefeuvre)
pam-python
NOTE: 20190927: Upstream appear to not have a distinct revision for this fix, using a single commit for the entire release which changes many things. (lamby)
--
+polar-ssl
+--
radare2
NOTE: 20190816: Affected by CVE-2019-14745. Vulnerable code is in
NOTE: libr/core/bin.c. Many no-dsa issues in Jessie and Stretch.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/6a10756d72fb33fc9cc3a9324e067e349781e9e9...3ca8216af118e47d9d96cc8ab2898aeb3db0c13e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/6a10756d72fb33fc9cc3a9324e067e349781e9e9...3ca8216af118e47d9d96cc8ab2898aeb3db0c13e
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191002/f41a352a/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list