[Git][security-tracker-team/security-tracker][master] Reserve DLA-2735-1 for ceph

Markus Koschany (@apo) apo at debian.org
Mon Aug 9 10:11:40 BST 2021



Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a52bf959 by Markus Koschany at 2021-08-09T11:11:33+02:00
Reserve DLA-2735-1 for ceph

- - - - -


2 changed files:

- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[09 Aug 2021] DLA-2735-1 ceph - security update
+	{CVE-2018-14662 CVE-2018-16846 CVE-2020-1760 CVE-2020-10753 CVE-2021-3524}
+	[stretch] - ceph 10.2.11-2+deb9u1
 [09 Aug 2021] DLA-2734-1 curl - security update
 	{CVE-2021-22898 CVE-2021-22924}
 	[stretch] - curl 7.52.1-5+deb9u15


=====================================
data/dla-needed.txt
=====================================
@@ -24,16 +24,6 @@ ansible
 asterisk (Chris Lamb)
   NOTE: 20210807: Double-check it applies; upstream's patch is actually a patch to an embedded code copy. (lamby)
 --
-ceph (Markus Koschany)
-  NOTE: 20200707: Vulnerable to at least CVE-2018-14662. (lamby)
-  NOTE: 20200707: Some discussion regarding removal <https://lists.debian.org/debian-lts/2020/04/msg00019.html> (lamby)
-  NOTE: 20200913: Patches prepared. Build in progress (hope this 45 G build goes fine). (ola)
-  NOTE: 20200928: Packages prepared and available at http://apt.inguza.net/stretch-lts/ceph/
-  NOTE: 20200928: If someone know how to test the packages please take this build and upload (after testing it).
-  NOTE: 20210118: wip (Emilio)
-  NOTE: 20210726: https://people.debian.org/~apo/lts/ceph/
-  NOTE: 20210726: Patch for CVE-2018-16846 is not complete yet.
---
 commons-io (Markus Koschany)
 --
 exiv2 (Utkarsh Gupta)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a52bf9590ee0fdc00daa46ddafcd95eef48ea254

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a52bf9590ee0fdc00daa46ddafcd95eef48ea254
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210809/441a5c61/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list