[Git][security-tracker-team/security-tracker][master] 2 commits: LTS: Remove no-dsa tags from CVE-2019-13115 and CVE-2019-17498
Anton Gladky (@gladk)
gladk at debian.org
Fri Dec 17 20:26:11 GMT 2021
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker
Commits:
99497495 by Anton Gladky at 2021-12-17T21:25:21+01:00
LTS: Remove no-dsa tags from CVE-2019-13115 and CVE-2019-17498
- - - - -
3130560d by Anton Gladky at 2021-12-17T21:25:22+01:00
Reserve DLA-2848-1 for libssh2
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -152922,7 +152922,6 @@ CVE-2019-17498 (In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT l
{DLA-1991-1}
- libssh2 1.9.0-1 (low; bug #943562)
[buster] - libssh2 <no-dsa> (Minor issue)
- [stretch] - libssh2 <no-dsa> (Minor issue)
NOTE: https://github.com/libssh2/libssh2/commit/dedcbd106f8e52d5586b0205bc7677e4c9868f9c
NOTE: https://securitylab.github.com/research/libssh2-integer-overflow-CVE-2019-17498/
NOTE: Backported SUSE patch for versions <= 1.8.0 (including struct string_buf,
@@ -167489,7 +167488,6 @@ CVE-2019-13115 (In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchang
{DLA-1730-3}
- libssh2 1.9.0-1 (bug #932329)
[buster] - libssh2 <no-dsa> (Minor issue)
- [stretch] - libssh2 <no-dsa> (Minor issue)
NOTE: https://securitylab.github.com/research/libssh2-integer-overflow/
NOTE: https://github.com/libssh2/libssh2/pull/350
NOTE: https://github.com/libssh2/libssh2/commit/ff1b155731ff8f790f12d980911d9fd84d0e1598
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[17 Dec 2021] DLA-2848-1 libssh2 - security update
+ {CVE-2019-13115 CVE-2019-17498}
+ [stretch] - libssh2 1.7.0-1+deb9u2
[15 Dec 2021] DLA-2847-1 mediawiki - security update
{CVE-2021-44858}
[stretch] - mediawiki 1:1.27.7-1+deb9u11
=====================================
data/dla-needed.txt
=====================================
@@ -53,11 +53,6 @@ libgit2 (Utkarsh)
NOTE: 20211129: readied up everything, using pygit and other wrappers
NOTE: 20211129: around which the code changed. will upload in the next 2 days. (utkarsh)
--
-libssh2 (Anton)
- NOTE: 20211031: CVE-2019-13115 and CVE-2019-17498 were fixed in jessie DLAs
- NOTE: 20211031: but still need fixing in stretch and buster. (bunk)
- NOTE: 20211116: Work in progress for stretch. (ola)
---
linux (Ben Hutchings)
--
linux-4.19 (Ben Hutchings)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/83ac707edf0f51cf06eb8398f26da9ab0e3cab39...3130560d848a76c83ccd5df09fd503cfd81726f1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/83ac707edf0f51cf06eb8398f26da9ab0e3cab39...3130560d848a76c83ccd5df09fd503cfd81726f1
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211217/1ce82911/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list