[Git][security-tracker-team/security-tracker][master] Reserve DLA-2834-1 for uriparser
Adrian Bunk (@bunk)
bunk at debian.org
Tue Nov 30 23:29:21 GMT 2021
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7a79b21c by Adrian Bunk at 2021-11-30T23:29:07+00:00
Reserve DLA-2834-1 for uriparser
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -184417,7 +184417,6 @@ CVE-2018-20722
CVE-2018-20721 (URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bound ...)
{DLA-1682-1}
- uriparser 0.9.1-1 (low)
- [stretch] - uriparser <no-dsa> (Minor issue)
NOTE: https://github.com/uriparser/uriparser/commit/cef25028de5ff872c2e1f0a6c562eb3ea9ecbce4
CVE-2015-9280 (MailEnable before 8.60 allows XXE via an XML document in the request.a ...)
NOT-FOR-US: MailEnable
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[30 Nov 2021] DLA-2834-1 uriparser - security update
+ {CVE-2018-20721}
+ [stretch] - uriparser 0.8.4-1+deb9u2
[30 Nov 2021] DLA-2833-1 rsync - security update
{CVE-2018-5764}
[stretch] - rsync 3.1.2-1+deb9u3
=====================================
data/dla-needed.txt
=====================================
@@ -100,8 +100,6 @@ samba (Anton)
thunderbird (Emilio)
NOTE: 20211122: blocked on toolchain backports (pochu)
--
-uriparser (Adrian Bunk)
---
wireshark (Adrian Bunk)
NOTE: 20211119: Check https://salsa.debian.org/security-tracker-team/security-tracker/commit/d55b7eff90db8487e20106c2c09e61293a477e89 (lamby)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a79b21c6dba9287174970dc57510ed58539d36f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a79b21c6dba9287174970dc57510ed58539d36f
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211130/d8aabd24/attachment.htm>
More information about the debian-security-tracker-commits
mailing list