[Git][security-tracker-team/security-tracker][master] 4 commits: add xmlbeans

Thorsten Alteholz alteholz at debian.org
Sat Jan 23 00:05:12 GMT 2021



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
33a542d1 by Thorsten Alteholz at 2021-01-23T00:51:39+01:00
add xmlbeans

- - - - -
1b320853 by Thorsten Alteholz at 2021-01-23T00:59:24+01:00
mark CVE-2020-27827 as no-dsa for openvswitch in Stretch

- - - - -
c0a091b7 by Thorsten Alteholz at 2021-01-23T01:03:33+01:00
nark CVE-2015-8011 as no-dsa for openvswitch in Stretch

- - - - -
6f9d65ea by Thorsten Alteholz at 2021-01-23T01:04:54+01:00
xen is EOL in Stretch

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -758,6 +758,7 @@ CVE-2019-25014
 CVE-2021-XXXX [Xen: IRQ vector leak on x86]
 	- xen <unfixed>
 	[buster] - xen <postponed> (Fix along in future update)
+	[stretch] - xen <end-of-life> (DSA 4602-1)
 	NOTE: https://xenbits.xen.org/xsa/advisory-360.html
 CVE-2021-3189
 	RESERVED
@@ -23823,6 +23824,7 @@ CVE-2020-27827 [lldp: avoid memory leak from bad packets]
 	[buster] - lldpd <no-dsa> (Minor issue)
 	[stretch] - lldpd <no-dsa> (Minor issue)
 	- openvswitch 2.15.0~git20210104.def6eb1ea+dfsg1-4 (bug #980132)
+	[stretch] - openvswitch <no-dsa> (Minor issue)
 	NOTE: https://github.com/openvswitch/ovs/pull/337
 	NOTE: https://github.com/lldpd/lldpd/commit/a8d3c90feca548fc0656d95b5d278713db86ff61
 	NOTE: https://mail.openvswitch.org/pipermail/ovs-announce/2021-January/000269.html
@@ -288580,6 +288582,7 @@ CVE-2015-8011 (Buffer overflow in the lldp_decode function in daemon/protocols/l
 	[wheezy] - lldpd <not-affected> (Vulnerable code not present)
 	[squeeze] - lldpd <not-affected> (Vulnerable code not present)
 	- openvswitch 2.15.0~git20210104.def6eb1ea+dfsg1-1
+	[stretch] - openvswitch <no-dsa> (Minor issue)
 	NOTE: https://github.com/lldpd/lldpd/commit/dd4f16e7e816f2165fba76e3d162cd8d2978dcb2
 	NOTE: https://www.openwall.com/lists/oss-security/2015/10/16/2
 	NOTE: https://mail.openvswitch.org/pipermail/ovs-announce/2021-January/000268.html


=====================================
data/dla-needed.txt
=====================================
@@ -156,3 +156,5 @@ xcftools
   NOTE: 20200523: Proposed fix https://github.com/j-jorge/xcftools/pull/15 (gladk)
   NOTE: 20200605: Patch https://salsa.debian.org/lts-team/packages/xcftools/-/blob/fix/test-CVE-2019-5087/debian/patches/CVE-2019-5087.patch (gladk)
 --
+xmlbeans
+--



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/63a4a42f5df8fc3030ad1422c54ef7cee6932367...6f9d65ead4a541a2b075150ec45382eb576e6db7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/63a4a42f5df8fc3030ad1422c54ef7cee6932367...6f9d65ead4a541a2b075150ec45382eb576e6db7
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210123/9dc037fc/attachment.html>


More information about the debian-security-tracker-commits mailing list