[Git][security-tracker-team/security-tracker][master] dla: drop roundcube

Sylvain Beucler (@beuc) beuc at debian.org
Tue Jul 20 17:43:05 BST 2021



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a546fca0 by Sylvain Beucler at 2021-07-20T18:42:47+02:00
dla: drop roundcube

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -72583,11 +72583,13 @@ CVE-2020-18672
 CVE-2020-18671 (Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4  ...)
 	- roundcube 1.4.5+dfsg.1-1
 	[buster] - roundcube 1.3.13+dfsg.1-1~deb10u1
+	[stretch] - roundcube <postponed> (Minor issue, XSS in installer which is not exposed in Debian)
 	NOTE: https://github.com/roundcube/roundcubemail/issues/7406
 	NOTE: https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12
 CVE-2020-18670 (Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via d ...)
 	- roundcube 1.4.5+dfsg.1-1
 	[buster] - roundcube 1.3.13+dfsg.1-1~deb10u1
+	[stretch] - roundcube <postponed> (Minor issue, XSS in installer which is not exposed in Debian)
 	NOTE: https://github.com/roundcube/roundcubemail/issues/7406
 	NOTE: https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12
 CVE-2020-18669


=====================================
data/dla-needed.txt
=====================================
@@ -79,9 +79,6 @@ python-babel
  NOTE: 20210620: http://people.debian.org/~abhijith/backport_of_3a700b5.patch (abhijith)
  NOTE: 20210620: Revisit when it have an assigned CVE Id. (abhijith)
 --
-roundcube
-  NOTE: 20210706: Check with maintainer as they have handled previous uploads. (lamby)
---
 ruby-actionpack-page-caching
   NOTE: 20200819: Upstream's patch on does not apply due to subsequent
   NOTE: 20200819: refactoring. However, a quick look at the private



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a546fca001916e76fff8c55aec151322dcc8c04e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a546fca001916e76fff8c55aec151322dcc8c04e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210720/b5e313f9/attachment.htm>


More information about the debian-security-tracker-commits mailing list