[Git][security-tracker-team/security-tracker][master] 5 commits: data/dla-needed.txt: Triage wireshark for stretch LTS (CVE-2021-39920,...
Chris Lamb (@lamby)
lamby at debian.org
Fri Nov 19 20:15:03 GMT 2021
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
acac39f3 by Chris Lamb at 2021-11-19T12:12:34-08:00
data/dla-needed.txt: Triage wireshark for stretch LTS (CVE-2021-39920, CVE-2021-39921, CVE-2021-39922, CVE-2021-39924, CVE-2021-39925, CVE-2021-39926, CVE-2021-39928 & CVE-2021-39929)
- - - - -
98ca768c by Chris Lamb at 2021-11-19T12:13:25-08:00
Triage CVE-2021-3975 in libvirt for stretch LTS.
- - - - -
12a056ae by Chris Lamb at 2021-11-19T12:13:56-08:00
Triage CVE-2021-43519 in lua5.1 for stretch LTS.
- - - - -
f1b7135f by Chris Lamb at 2021-11-19T12:14:14-08:00
Triage CVE-2021-43519 in lua5.2 for stretch LTS.
- - - - -
52a93500 by Chris Lamb at 2021-11-19T12:14:29-08:00
Triage CVE-2021-43519 in lua5.3 for stretch LTS.
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -99,6 +99,7 @@ CVE-2021-3975 [segmentation fault during VM shutdown can lead to vdsm hung]
- libvirt 7.6.0-1
[bullseye] - libvirt <no-dsa> (Minor issue)
[buster] - libvirt <no-dsa> (Minor issue)
+ [stretch] - libvirt <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2024326
NOTE: Fixed by: https://github.com/libvirt/libvirt/commit/1ac703a7d0789e46833f4013a3876c2e3af18ec7 (v7.1.0-rc2)
CVE-2021-44025 (Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in han ...)
@@ -2259,12 +2260,15 @@ CVE-2021-43519 (Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5
- lua5.3 <unfixed>
[bullseye] - lua5.3 <no-dsa> (Minor issue)
[buster] - lua5.3 <no-dsa> (Minor issue)
+ [stretch] - lua5.3 <no-dsa> (Minor issue)
- lua5.2 <unfixed>
[bullseye] - lua5.2 <no-dsa> (Minor issue)
[buster] - lua5.2 <no-dsa> (Minor issue)
+ [stretch] - lua5.2 <no-dsa> (Minor issue)
- lua5.1 <unfixed>
[bullseye] - lua5.1 <no-dsa> (Minor issue)
[buster] - lua5.1 <no-dsa> (Minor issue)
+ [stretch] - lua5.1 <no-dsa> (Minor issue)
NOTE: http://lua-users.org/lists/lua-l/2021-10/msg00123.html
NOTE: http://lua-users.org/lists/lua-l/2021-11/msg00015.html
NOTE: Fixed by: https://github.com/lua/lua/commit/74d99057a5146755e737c479850f87fd0e3b6868
=====================================
data/dla-needed.txt
=====================================
@@ -96,3 +96,6 @@ samba (Anton)
thunderbird (Emilio)
NOTE: 20211116: blocked on toolchain backports (pochu)
--
+wireshark
+ NOTE: 20211119: Check https://salsa.debian.org/security-tracker-team/security-tracker/commit/d55b7eff90db8487e20106c2c09e61293a477e89 (lamby)
+--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a7cb0e27fb20261bb20c9b995d9216f328a911a8...52a93500680da92ff46ca2288fb2a6da321d0cb8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a7cb0e27fb20261bb20c9b995d9216f328a911a8...52a93500680da92ff46ca2288fb2a6da321d0cb8
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211119/d9d1fd65/attachment.htm>
More information about the debian-security-tracker-commits
mailing list