[Git][security-tracker-team/security-tracker][master] 3 commits: LTS: Add note aboue CVE-2021-32920 f0r stretch
Anton Gladky (@gladk)
gladk at debian.org
Tue Jun 15 21:43:06 BST 2021
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1ffcd211 by Anton Gladky at 2021-06-15T22:42:50+02:00
LTS: Add note aboue CVE-2021-32920 f0r stretch
- - - - -
0ed7dc74 by Anton Gladky at 2021-06-15T22:42:50+02:00
Reserve DLA-2687-1 for prosody
- - - - -
7285bb9a by Anton Gladky at 2021-06-15T22:42:50+02:00
LTS: take scilab
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -3980,6 +3980,7 @@ CVE-2021-32921 (An issue was discovered in Prosody before 0.11.9. It does not us
CVE-2021-32920 (Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood ...)
{DSA-4916-1}
- prosody 0.11.9-1 (bug #988668)
+ [stretch] - prosody <ignored> (Fix is consisting of many patches. Not appliable. Ingored)
NOTE: https://www.openwall.com/lists/oss-security/2021/05/13/1
NOTE: https://prosody.im/security/advisory_20210512.txt
NOTE: https://hg.prosody.im/trunk/rev/55ef50d6cf65
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[15 Jun 2021] DLA-2687-1 prosody - security update
+ {CVE-2021-32917 CVE-2021-32921}
+ [stretch] - prosody 0.9.12-2+deb9u3
[15 Jun 2021] DLA-2686-1 python-urllib3 - security update
{CVE-2018-20060 CVE-2019-11236 CVE-2019-11324 CVE-2020-26137}
[stretch] - python-urllib3 1.19.1-1+deb9u1
=====================================
data/dla-needed.txt
=====================================
@@ -75,11 +75,6 @@ nvidia-graphics-drivers
--
openexr
--
-prosody (Anton Gladky)
- NOTE: 20210519: at least the 10MB limit mentioned in CVE-2021-32918 is present
- NOTE: 20210530: WIP
- NOTE: 20210613: WIP
---
python-babel (Abhijith PA)
--
python-pip (Abhijith PA)
@@ -113,7 +108,7 @@ salt
NOTE: 20210510: will try to release ASAP; also preparing update for buster (DSA). (utkarsh)
NOTE: 20210607: new CVE patch proposed by damien; donfede to provide a debdiff. (utkarsh)
--
-scilab
+scilab (Anton Gladky)
NOTE: 20210615: vulnerability in embedded ezXML.(abhijith)
--
shiro (Roberto C. Sánchez)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/8beba61e4e8eb176c1692f5fe30a2d3ba17169e8...7285bb9ab5c1db89a86e0dcadd4bc2cb55566f36
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/8beba61e4e8eb176c1692f5fe30a2d3ba17169e8...7285bb9ab5c1db89a86e0dcadd4bc2cb55566f36
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210615/6c0aa323/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list