[Git][security-tracker-team/security-tracker][master] Reserve DLA-1971-1 for libarchive

Thorsten Alteholz alteholz at debian.org
Sat Oct 26 22:23:57 BST 2019



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
646b42db by Thorsten Alteholz at 2019-10-26T21:24:53Z
Reserve DLA-1971-1 for libarchive

- - - - -


2 changed files:

- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[26 Oct 2019] DLA-1971-1 libarchive - security update
+	{CVE-2019-18408}
+	[jessie] - libarchive 3.1.2-11+deb8u8
 [26 Oct 2019] DLA-1970-1 php5 - security update
 	{CVE-2019-11043}
 	[jessie] - php5 5.6.40+dfsg-0+deb8u7


=====================================
data/dla-needed.txt
=====================================
@@ -44,8 +44,6 @@ libapache2-mod-auth-openidc
   NOTE: 20191011: Upstream patch tightens validation but jessie does not appear
   NOTE: 20191011: to have any validation whatsoever on first glance. (lamby)
 --
-libarchive (Thorsten Alteholz)
---
 libav
   NOTE: 20190831: There are currently 19 CVE issues known for libav in jessie,
   NOTE: 20190831: 11 tagged as <no-dsa>. These issues have been triaged, no patch



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/646b42dbdc7fc76adfd1511fdface04a8d2e96c6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/646b42dbdc7fc76adfd1511fdface04a8d2e96c6
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191026/1c70cd9c/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list