[Git][security-tracker-team/security-tracker][master] 4 commits: add xmlbeans
Thorsten Alteholz
alteholz at debian.org
Sat Jan 23 00:05:12 GMT 2021
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
33a542d1 by Thorsten Alteholz at 2021-01-23T00:51:39+01:00
add xmlbeans
- - - - -
1b320853 by Thorsten Alteholz at 2021-01-23T00:59:24+01:00
mark CVE-2020-27827 as no-dsa for openvswitch in Stretch
- - - - -
c0a091b7 by Thorsten Alteholz at 2021-01-23T01:03:33+01:00
nark CVE-2015-8011 as no-dsa for openvswitch in Stretch
- - - - -
6f9d65ea by Thorsten Alteholz at 2021-01-23T01:04:54+01:00
xen is EOL in Stretch
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -758,6 +758,7 @@ CVE-2019-25014
CVE-2021-XXXX [Xen: IRQ vector leak on x86]
- xen <unfixed>
[buster] - xen <postponed> (Fix along in future update)
+ [stretch] - xen <end-of-life> (DSA 4602-1)
NOTE: https://xenbits.xen.org/xsa/advisory-360.html
CVE-2021-3189
RESERVED
@@ -23823,6 +23824,7 @@ CVE-2020-27827 [lldp: avoid memory leak from bad packets]
[buster] - lldpd <no-dsa> (Minor issue)
[stretch] - lldpd <no-dsa> (Minor issue)
- openvswitch 2.15.0~git20210104.def6eb1ea+dfsg1-4 (bug #980132)
+ [stretch] - openvswitch <no-dsa> (Minor issue)
NOTE: https://github.com/openvswitch/ovs/pull/337
NOTE: https://github.com/lldpd/lldpd/commit/a8d3c90feca548fc0656d95b5d278713db86ff61
NOTE: https://mail.openvswitch.org/pipermail/ovs-announce/2021-January/000269.html
@@ -288580,6 +288582,7 @@ CVE-2015-8011 (Buffer overflow in the lldp_decode function in daemon/protocols/l
[wheezy] - lldpd <not-affected> (Vulnerable code not present)
[squeeze] - lldpd <not-affected> (Vulnerable code not present)
- openvswitch 2.15.0~git20210104.def6eb1ea+dfsg1-1
+ [stretch] - openvswitch <no-dsa> (Minor issue)
NOTE: https://github.com/lldpd/lldpd/commit/dd4f16e7e816f2165fba76e3d162cd8d2978dcb2
NOTE: https://www.openwall.com/lists/oss-security/2015/10/16/2
NOTE: https://mail.openvswitch.org/pipermail/ovs-announce/2021-January/000268.html
=====================================
data/dla-needed.txt
=====================================
@@ -156,3 +156,5 @@ xcftools
NOTE: 20200523: Proposed fix https://github.com/j-jorge/xcftools/pull/15 (gladk)
NOTE: 20200605: Patch https://salsa.debian.org/lts-team/packages/xcftools/-/blob/fix/test-CVE-2019-5087/debian/patches/CVE-2019-5087.patch (gladk)
--
+xmlbeans
+--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/63a4a42f5df8fc3030ad1422c54ef7cee6932367...6f9d65ead4a541a2b075150ec45382eb576e6db7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/63a4a42f5df8fc3030ad1422c54ef7cee6932367...6f9d65ead4a541a2b075150ec45382eb576e6db7
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210123/9dc037fc/attachment.html>
More information about the debian-security-tracker-commits
mailing list