[Git][security-tracker-team/security-tracker][master] Reserve DLA-2834-1 for uriparser

Adrian Bunk (@bunk) bunk at debian.org
Tue Nov 30 23:29:21 GMT 2021



Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7a79b21c by Adrian Bunk at 2021-11-30T23:29:07+00:00
Reserve DLA-2834-1 for uriparser

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -184417,7 +184417,6 @@ CVE-2018-20722
 CVE-2018-20721 (URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bound ...)
 	{DLA-1682-1}
 	- uriparser 0.9.1-1 (low)
-	[stretch] - uriparser <no-dsa> (Minor issue)
 	NOTE: https://github.com/uriparser/uriparser/commit/cef25028de5ff872c2e1f0a6c562eb3ea9ecbce4
 CVE-2015-9280 (MailEnable before 8.60 allows XXE via an XML document in the request.a ...)
 	NOT-FOR-US: MailEnable


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[30 Nov 2021] DLA-2834-1 uriparser - security update
+	{CVE-2018-20721}
+	[stretch] - uriparser 0.8.4-1+deb9u2
 [30 Nov 2021] DLA-2833-1 rsync - security update
 	{CVE-2018-5764}
 	[stretch] - rsync 3.1.2-1+deb9u3


=====================================
data/dla-needed.txt
=====================================
@@ -100,8 +100,6 @@ samba (Anton)
 thunderbird (Emilio)
   NOTE: 20211122: blocked on toolchain backports (pochu)
 --
-uriparser (Adrian Bunk)
---
 wireshark (Adrian Bunk)
   NOTE: 20211119: Check https://salsa.debian.org/security-tracker-team/security-tracker/commit/d55b7eff90db8487e20106c2c09e61293a477e89 (lamby)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a79b21c6dba9287174970dc57510ed58539d36f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a79b21c6dba9287174970dc57510ed58539d36f
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211130/d8aabd24/attachment.htm>


More information about the debian-security-tracker-commits mailing list