[Git][security-tracker-team/security-tracker][master] 2 commits: Strip no-dsa tags for opendmarc for stretch which'll receieve an update

Utkarsh Gupta utkarsh at debian.org
Sun Apr 25 08:46:22 BST 2021



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4ae084e4 by Utkarsh Gupta at 2021-04-25T12:59:25+05:30
Strip no-dsa tags for opendmarc for stretch which'll receieve an update

- - - - -
d4da7d4d by Utkarsh Gupta at 2021-04-25T13:16:11+05:30
Reserve DLA-2639-1 for opendmarc

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -74313,7 +74313,6 @@ CVE-2020-12461 (PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has
 CVE-2020-12460 (OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper nul ...)
 	- opendmarc 1.4.0~beta1+dfsg-3 (bug #966464)
 	[buster] - opendmarc <no-dsa> (Minor issue)
-	[stretch] - opendmarc <no-dsa> (Minor issue)
 	NOTE: https://github.com/trusteddomainproject/OpenDMARC/issues/64
 	NOTE: https://github.com/trusteddomainproject/OpenDMARC/commit/50d28af25d8735504b6103537228ce7f76ad765f
 CVE-2020-12459 (In certain Red Hat packages for Grafana 6.x through 6.3.6, the configu ...)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[25 Apr 2021] DLA-2639-1 opendmarc - security update
+	{CVE-2020-12460}
+	[stretch] - opendmarc 1.3.2-2+deb9u3
 [25 Apr 2021] DLA-2638-1 jackson-databind - security update
 	{CVE-2020-24616 CVE-2020-24750 CVE-2020-35490 CVE-2020-35491 CVE-2020-35728 CVE-2020-36179 CVE-2020-36180 CVE-2020-36181 CVE-2020-36182 CVE-2020-36183 CVE-2020-36184 CVE-2020-36185 CVE-2020-36186 CVE-2020-36187 CVE-2020-36188 CVE-2020-36189 CVE-2021-20190}
 	[stretch] - jackson-databind 2.8.6-1+deb9u9


=====================================
data/dla-needed.txt
=====================================
@@ -85,11 +85,6 @@ nvidia-graphics-drivers
   NOTE: package is in non-free but also in packages-to-support
   NOTE: only CVE‑2021‑1076 seems to be fixed in the R390 branch used in Stretch, no fix available for CVE-2021-1077
 --
-opendmarc (Utkarsh)
-  NOTE: 20200719: no patches for remaining CVEs available, everything else is already done in Stretch (thorsten)
-  NOTE: 20201217: patch for CVE-2020-12460 has become available (roberto)
-  NOTE: 20210104: wait for other CVEs (abhijith)
---
 openexr
 --
 ring (Thorsten Alteholz)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fa663333458a736a7fd8d4c592f29e24b4cbe2dd...d4da7d4da4aa9f6017df68d94d20c2ec3f54ca2e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fa663333458a736a7fd8d4c592f29e24b4cbe2dd...d4da7d4da4aa9f6017df68d94d20c2ec3f54ca2e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210425/4a9640b7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list