[Git][security-tracker-team/security-tracker][master] Reserve DLA-2100-1 for libexif
Hugo Lefeuvre
hle at debian.org
Mon Feb 10 13:09:54 GMT 2020
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3b1702bf by Hugo Lefeuvre at 2020-02-10T14:09:43+01:00
Reserve DLA-2100-1 for libexif
- - - - -
2 changed files:
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[10 Feb 2020] DLA-2100-1 libexif - security update
+ {CVE-2019-9278}
+ [jessie] - libexif 0.6.21-2+deb8u1
[10 Feb 2020] DLA-2099-1 checkstyle - security update
{CVE-2019-10782}
[jessie] - checkstyle 5.9-1+deb8u2
=====================================
data/dla-needed.txt
=====================================
@@ -27,16 +27,6 @@ intel-microcode
jackson-databind
NOTE: 20200105: Can be postponed again. (apo)
--
-libexif
- NOTE: 20191111: Contacted upstream for relevant commits of CVE-2019-9278. (utkarsh2102)
- NOTE: 20191114: Pinged upstream; just have the Android patch yet. (utkarsh2102)
- NOTE: 20191118: No patch yet. Shall claim and fix once the patch is available. (utkarsh2102)
- NOTE: 20191201: Pinged the upstream yet again. (utkarsh2102)
- NOTE: 20191216: The android patch does not apply but is easy to manually apply. (ola)
- NOTE: 20191216: The problem is the file to trigger the fault is not known. (ola)
- NOTE: 20200111: Investigated the issue, currently in contact with Ray Essick @google
- NOTE: 20200111: to get access to the reproducer. (hle)
---
libmatio (Adrian Bunk)
NOTE: fairly high number of open issues. Not sure why we never had a look at them.
NOTE: triage work needed, help security team for fixes if needed.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/3b1702bffe1719c0a61c23522f81f8be5757e6a8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/3b1702bffe1719c0a61c23522f81f8be5757e6a8
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200210/340212e3/attachment.html>
More information about the debian-security-tracker-commits
mailing list