[Git][security-tracker-team/security-tracker][master] Reserve DLA-1971-1 for libarchive
Thorsten Alteholz
alteholz at debian.org
Sat Oct 26 22:23:57 BST 2019
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
646b42db by Thorsten Alteholz at 2019-10-26T21:24:53Z
Reserve DLA-1971-1 for libarchive
- - - - -
2 changed files:
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[26 Oct 2019] DLA-1971-1 libarchive - security update
+ {CVE-2019-18408}
+ [jessie] - libarchive 3.1.2-11+deb8u8
[26 Oct 2019] DLA-1970-1 php5 - security update
{CVE-2019-11043}
[jessie] - php5 5.6.40+dfsg-0+deb8u7
=====================================
data/dla-needed.txt
=====================================
@@ -44,8 +44,6 @@ libapache2-mod-auth-openidc
NOTE: 20191011: Upstream patch tightens validation but jessie does not appear
NOTE: 20191011: to have any validation whatsoever on first glance. (lamby)
--
-libarchive (Thorsten Alteholz)
---
libav
NOTE: 20190831: There are currently 19 CVE issues known for libav in jessie,
NOTE: 20190831: 11 tagged as <no-dsa>. These issues have been triaged, no patch
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/646b42dbdc7fc76adfd1511fdface04a8d2e96c6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/646b42dbdc7fc76adfd1511fdface04a8d2e96c6
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191026/1c70cd9c/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list