[Git][security-tracker-team/security-tracker][master] Reserve DLA-2545-1 for open-build-service
Utkarsh Gupta
utkarsh at debian.org
Wed Feb 3 12:25:24 GMT 2021
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ddcf4109 by Utkarsh Gupta at 2021-02-03T17:55:09+05:30
Reserve DLA-2545-1 for open-build-service
- - - - -
2 changed files:
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[03 Feb 2021] DLA-2545-1 open-build-service - security update
+ {CVE-2020-8020 CVE-2020-8021}
+ [stretch] - open-build-service 2.7.1-10+deb9u1
[03 Feb 2021] DLA-2544-1 openldap - security update
{CVE-2020-36221 CVE-2020-36222 CVE-2020-36223 CVE-2020-36224 CVE-2020-36225 CVE-2020-36226 CVE-2020-36227 CVE-2020-36228 CVE-2020-36229 CVE-2020-36230}
[stretch] - openldap 2.4.44+dfsg-5+deb9u7
=====================================
data/dla-needed.txt
=====================================
@@ -56,11 +56,6 @@ mumble
NOTE: 20200504: discussion going on with team at security.debian.org and mumble maintainer (abhijith)
NOTE: 20200723: https://lists.debian.org/debian-lts/2020/05/msg00008.html (abhijith)
--
-open-build-service (Utkarsh)
- NOTE: 20201001: upstream is yet to work on CVE-2020-8021. Pinged them.
- NOTE: 20201001: cf: https://bugzilla.suse.com/show_bug.cgi?id=1171649 (utkarsh)
- NOTE: 20201122: regression noticed; let the fix be exposed in sid for a week or two. (utkarsh)
---
opendmarc
NOTE: 20200719: no patches for remaining CVEs available, everything else is already done in Stretch (thorsten)
NOTE: 20201217: patch for CVE-2020-12460 has become available (roberto)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ddcf4109aaf0109e8f0e0753907bda05146fb334
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ddcf4109aaf0109e8f0e0753907bda05146fb334
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210203/e32199f2/attachment.html>
More information about the debian-security-tracker-commits
mailing list