[Git][security-tracker-team/security-tracker][master] 2 commits: Mark CVE-2019-17134/octavia as no-dsa
Salvatore Bonaccorso
carnil at debian.org
Mon Oct 7 21:41:41 BST 2019
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
564a6093 by Salvatore Bonaccorso at 2019-10-07T20:40:19Z
Mark CVE-2019-17134/octavia as no-dsa
- - - - -
0c2b3825 by Salvatore Bonaccorso at 2019-10-07T20:41:03Z
Track proposed fix for CVE-2019-17134 via buster-pu
- - - - -
2 changed files:
- data/CVE/list
- data/next-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -387,6 +387,7 @@ CVE-2019-17135
CVE-2019-17134 [agent doesn't check for client certificate]
RESERVED
- octavia 4.0.0-6 (bug #941897)
+ [buster] - octavia <no-dsa> (Minor issue in regular setups, can be fixed via point release)
CVE-2019-17132 (vBulletin through 5.5.4 mishandles custom avatars. ...)
NOT-FOR-US: vBulletin
CVE-2019-17131 (vBulletin before 5.5.4 allows clickjacking. ...)
=====================================
data/next-point-update.txt
=====================================
@@ -38,3 +38,5 @@ CVE-2019-10747
[buster] - node-set-value 0.4.0-1+deb10u1
CVE-2019-5448
[buster] - node-yarnpkg 1.13.0-1+deb10u1
+CVE-2019-17134
+ [buster] - octavia 3.0.0-3+deb10u1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/4912c6581cc4a0b4f07ed72069907e5b6a8a6b40...0c2b3825808cda02c060668abc66f1534595752d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/4912c6581cc4a0b4f07ed72069907e5b6a8a6b40...0c2b3825808cda02c060668abc66f1534595752d
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191007/dbdf3118/attachment.html>
More information about the debian-security-tracker-commits
mailing list