[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2021-27921,CVE-2021-27922,CVE-2021-27923/pillow: stretch triage
Sylvain Beucler
beuc at debian.org
Thu Mar 18 21:42:47 GMT 2021
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d289b03d by Sylvain Beucler at 2021-03-18T22:42:14+01:00
CVE-2021-27921,CVE-2021-27922,CVE-2021-27923/pillow: stretch triage
- - - - -
aaa040ac by Sylvain Beucler at 2021-03-18T22:42:15+01:00
CVE-2018-16428/glib2.0: fixed through stretch o-p-u (but typo in changelog)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2066,18 +2066,22 @@ CVE-2021-27924
CVE-2021-27923 (Pillow before 8.1.1 allows attackers to cause a denial of service (mem ...)
- pillow 8.1.2-1
[buster] - pillow <ignored> (Minor issue)
+ [stretch] - pillow <ignored> (Minor issue, risk of regression, _decompression_bomb_check only warned, see CVE-2019-16865)
NOTE: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html
NOTE: https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973
CVE-2021-27922 (Pillow before 8.1.1 allows attackers to cause a denial of service (mem ...)
- pillow 8.1.2-1
[buster] - pillow <ignored> (Minor issue)
+ [stretch] - pillow <ignored> (Minor issue, risk of regression, _decompression_bomb_check only warned, see CVE-2019-16865)
NOTE: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html
NOTE: https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973
CVE-2021-27921 (Pillow before 8.1.1 allows attackers to cause a denial of service (mem ...)
- pillow 8.1.2-1
[buster] - pillow <ignored> (Minor issue)
+ [stretch] - pillow <not-affected> (Vulnerable code introduced later)
NOTE: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html
NOTE: https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973
+ NOTE: Introduced in https://github.com/python-pillow/Pillow/commit/adaa70357662a11cd4b7c0beddaad4e92164c5d9 (5.1.0)
CVE-2021-27920
RESERVED
CVE-2021-27919 (archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a den ...)
@@ -165996,7 +166000,7 @@ CVE-2018-16429 (GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_m
CVE-2018-16428 (In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c ...)
{DLA-1866-1}
- glib2.0 2.58.0-1 (low)
- [stretch] - glib2.0 <no-dsa> (Minor issue)
+ [stretch] - glib2.0 2.50.3-2+deb9u1
NOTE: https://gitlab.gnome.org/GNOME/glib/commit/fccef3cc822af74699cca84cd202719ae61ca3b9
NOTE: https://gitlab.gnome.org/GNOME/glib/issues/1364
CVE-2018-16427 (Various out of bounds reads when handling responses in OpenSC before 0 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/651d8b67e8b8c5a0d52c39457840a6fdfb945260...aaa040ac94a53b8be5c9c2f7366ec50f878cb6e4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/651d8b67e8b8c5a0d52c39457840a6fdfb945260...aaa040ac94a53b8be5c9c2f7366ec50f878cb6e4
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210318/6d736480/attachment.htm>
More information about the debian-security-tracker-commits
mailing list