[Git][security-tracker-team/security-tracker][master] Reserve DLA-2545-1 for open-build-service

Utkarsh Gupta utkarsh at debian.org
Wed Feb 3 12:25:24 GMT 2021



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ddcf4109 by Utkarsh Gupta at 2021-02-03T17:55:09+05:30
Reserve DLA-2545-1 for open-build-service

- - - - -


2 changed files:

- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[03 Feb 2021] DLA-2545-1 open-build-service - security update
+	{CVE-2020-8020 CVE-2020-8021}
+	[stretch] - open-build-service 2.7.1-10+deb9u1
 [03 Feb 2021] DLA-2544-1 openldap - security update
 	{CVE-2020-36221 CVE-2020-36222 CVE-2020-36223 CVE-2020-36224 CVE-2020-36225 CVE-2020-36226 CVE-2020-36227 CVE-2020-36228 CVE-2020-36229 CVE-2020-36230}
 	[stretch] - openldap 2.4.44+dfsg-5+deb9u7


=====================================
data/dla-needed.txt
=====================================
@@ -56,11 +56,6 @@ mumble
   NOTE: 20200504: discussion going on with team at security.debian.org and mumble maintainer (abhijith)
   NOTE: 20200723: https://lists.debian.org/debian-lts/2020/05/msg00008.html (abhijith)
 --
-open-build-service (Utkarsh)
-  NOTE: 20201001: upstream is yet to work on CVE-2020-8021. Pinged them.
-  NOTE: 20201001: cf: https://bugzilla.suse.com/show_bug.cgi?id=1171649 (utkarsh)
-  NOTE: 20201122: regression noticed; let the fix be exposed in sid for a week or two. (utkarsh)
---
 opendmarc
   NOTE: 20200719: no patches for remaining CVEs available, everything else is already done in Stretch (thorsten)
   NOTE: 20201217: patch for CVE-2020-12460 has become available (roberto)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ddcf4109aaf0109e8f0e0753907bda05146fb334

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ddcf4109aaf0109e8f0e0753907bda05146fb334
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210203/e32199f2/attachment.html>


More information about the debian-security-tracker-commits mailing list