[Git][security-tracker-team/security-tracker][master] Reserve DLA-2708-1 for php7.0

Sylvain Beucler (@beuc) beuc at debian.org
Thu Jul 15 09:37:15 BST 2021



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
72b2fa1b by Sylvain Beucler at 2021-07-15T10:33:51+02:00
Reserve DLA-2708-1 for php7.0

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -35502,7 +35502,6 @@ CVE-2021-21702 (In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x
 	- php7.4 7.4.15-1
 	- php7.3 <removed>
 	- php7.0 <removed>
-	[stretch] - php7.0 <postponed> (Relatively minor issue, can be fixed with next update)
 	NOTE: Fixed in PHP 8.0.2, 7.4.15, 7.3.27
 	NOTE: PHP Bug: https://bugs.php.net/80672
 CVE-2021-21701
@@ -102576,7 +102575,6 @@ CVE-2020-7071 (In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0,
 	- php7.4 7.4.14-1
 	- php7.3 <removed>
 	- php7.0 <removed>
-	[stretch] - php7.0 <postponed> (Minor issue, can be fixed in next release.)
 	NOTE: Fixed in PHP 8.0.1, 7.4.14, 7.3.26
 	NOTE: PHP Bug: https://bugs.php.net/77423
 CVE-2020-7070 (In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below ...)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[15 Jul 2021] DLA-2708-1 php7.0 - security update
+	{CVE-2019-18218 CVE-2020-7071 CVE-2021-21702 CVE-2021-21704 CVE-2021-21705}
+	[stretch] - php7.0 7.0.33-0+deb9u11
 [12 Jul 2021] DLA-2707-1 sogo - security update
 	{CVE-2021-33054}
 	[stretch] - sogo 3.2.6-2+deb9u1


=====================================
data/dla-needed.txt
=====================================
@@ -80,8 +80,6 @@ nvidia-graphics-drivers
   NOTE: package is in non-free but also in packages-to-support
   NOTE: only CVE‑2021‑1076 seems to be fixed in the R390 branch used in Stretch, no fix available for CVE-2021-1077
 --
-php7.0 (Sylvain Beucler)
---
 python-babel
  NOTE: 20210617: CVE ID rejected. (abhijith)
  NOTE: 20210620: http://people.debian.org/~abhijith/backport_of_3a700b5.patch (abhijith)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72b2fa1bb700147a48b7dd89edadb5333114d218

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72b2fa1bb700147a48b7dd89edadb5333114d218
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210715/8e031f5d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list