[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2021-22097/libspring-java postponed in stretch

Emilio Pozuelo Monfort (@pochu) pochu at debian.org
Wed Nov 10 09:17:02 GMT 2021



Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fd14e8e5 by Emilio Pozuelo Monfort at 2021-11-10T09:55:54+01:00
CVE-2021-22097/libspring-java postponed in stretch

- - - - -
fc5480b2 by Emilio Pozuelo Monfort at 2021-11-10T10:03:59+01:00
Add fixing commit for CVE-2021-3933/openexr

- - - - -
52df4e4f by Emilio Pozuelo Monfort at 2021-11-10T10:16:27+01:00
Triage samba for stretch

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -134,6 +134,7 @@ CVE-2021-3933
 	- openexr <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2019783
 	NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=38912
+	NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/5a0adf1aba7d41c6b94ba167c0c4308d2eecfd17
 CVE-2021-43521
 	RESERVED
 CVE-2021-43520
@@ -54242,6 +54243,7 @@ CVE-2021-22097 (In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the S
 	NOT-FOR-US: Spring AMQP
 CVE-2021-22096 (In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older ...)
 	- libspring-java <unfixed>
+	[stretch] - libspring-java <postponed> (Minor issue)
 	NOTE: request for commit info https://github.com/spring-projects/spring-framework/issues/27647
 CVE-2021-22095
 	RESERVED


=====================================
data/dla-needed.txt
=====================================
@@ -95,5 +95,7 @@ salt (Markus Koschany)
   NOTE: 20210816: will test the provided debdiff; needs testing as regression spotted. (utkarsh)
   NOTE: 20211108: (apo) Testing requires a bit more time. Intend to release in a few days.
 --
+samba
+--
 thunderbird (Emilio)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a25966ca7b47010d65d6fe031b2632df660bf0b3...52df4e4fe258d2244e37adc2350c692fd647159d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a25966ca7b47010d65d6fe031b2632df660bf0b3...52df4e4fe258d2244e37adc2350c692fd647159d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211110/2ad85144/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list