[Git][security-tracker-team/security-tracker][master] 5 commits: data/dla-needed.txt: Triage wireshark for stretch LTS (CVE-2021-39920,...

Chris Lamb (@lamby) lamby at debian.org
Fri Nov 19 20:15:03 GMT 2021



Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker


Commits:
acac39f3 by Chris Lamb at 2021-11-19T12:12:34-08:00
data/dla-needed.txt: Triage wireshark for stretch LTS (CVE-2021-39920, CVE-2021-39921, CVE-2021-39922, CVE-2021-39924, CVE-2021-39925, CVE-2021-39926, CVE-2021-39928 & CVE-2021-39929)

- - - - -
98ca768c by Chris Lamb at 2021-11-19T12:13:25-08:00
Triage CVE-2021-3975 in libvirt for stretch LTS.

- - - - -
12a056ae by Chris Lamb at 2021-11-19T12:13:56-08:00
Triage CVE-2021-43519 in lua5.1 for stretch LTS.

- - - - -
f1b7135f by Chris Lamb at 2021-11-19T12:14:14-08:00
Triage CVE-2021-43519 in lua5.2 for stretch LTS.

- - - - -
52a93500 by Chris Lamb at 2021-11-19T12:14:29-08:00
Triage CVE-2021-43519 in lua5.3 for stretch LTS.

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -99,6 +99,7 @@ CVE-2021-3975 [segmentation fault during VM shutdown can lead to vdsm hung]
 	- libvirt 7.6.0-1
 	[bullseye] - libvirt <no-dsa> (Minor issue)
 	[buster] - libvirt <no-dsa> (Minor issue)
+	[stretch] - libvirt <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2024326
 	NOTE: Fixed by: https://github.com/libvirt/libvirt/commit/1ac703a7d0789e46833f4013a3876c2e3af18ec7 (v7.1.0-rc2)
 CVE-2021-44025 (Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in han ...)
@@ -2259,12 +2260,15 @@ CVE-2021-43519 (Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5
 	- lua5.3 <unfixed>
 	[bullseye] - lua5.3 <no-dsa> (Minor issue)
 	[buster] - lua5.3 <no-dsa> (Minor issue)
+	[stretch] - lua5.3 <no-dsa> (Minor issue)
 	- lua5.2 <unfixed>
 	[bullseye] - lua5.2 <no-dsa> (Minor issue)
 	[buster] - lua5.2 <no-dsa> (Minor issue)
+	[stretch] - lua5.2 <no-dsa> (Minor issue)
 	- lua5.1 <unfixed>
 	[bullseye] - lua5.1 <no-dsa> (Minor issue)
 	[buster] - lua5.1 <no-dsa> (Minor issue)
+	[stretch] - lua5.1 <no-dsa> (Minor issue)
 	NOTE: http://lua-users.org/lists/lua-l/2021-10/msg00123.html
 	NOTE: http://lua-users.org/lists/lua-l/2021-11/msg00015.html
 	NOTE: Fixed by: https://github.com/lua/lua/commit/74d99057a5146755e737c479850f87fd0e3b6868


=====================================
data/dla-needed.txt
=====================================
@@ -96,3 +96,6 @@ samba (Anton)
 thunderbird (Emilio)
   NOTE: 20211116: blocked on toolchain backports (pochu)
 --
+wireshark
+  NOTE: 20211119: Check https://salsa.debian.org/security-tracker-team/security-tracker/commit/d55b7eff90db8487e20106c2c09e61293a477e89 (lamby)
+--



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a7cb0e27fb20261bb20c9b995d9216f328a911a8...52a93500680da92ff46ca2288fb2a6da321d0cb8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a7cb0e27fb20261bb20c9b995d9216f328a911a8...52a93500680da92ff46ca2288fb2a6da321d0cb8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211119/d9d1fd65/attachment.htm>


More information about the debian-security-tracker-commits mailing list