[Git][security-tracker-team/security-tracker][master] 3 commits: mark CVE-2021-32272 as not-affected for Stretch

Thorsten Alteholz (@alteholz) alteholz at debian.org
Fri Oct 22 23:14:49 BST 2021



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1458892d by Thorsten Alteholz at 2021-10-22T23:48:42+02:00
mark CVE-2021-32272 as not-affected for Stretch

- - - - -
b7b3e59f by Thorsten Alteholz at 2021-10-22T23:48:43+02:00
mark CVE-2021-32273 as not-affected for Stretch

- - - - -
98289123 by Thorsten Alteholz at 2021-10-23T00:13:12+02:00
add mailman

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -26243,10 +26243,12 @@ CVE-2021-32274 (An issue was discovered in faad2 through 2.10.0. A heap-buffer-o
 	NOTE: https://github.com/knik0/faad2/commit/c78251b2b5d41ea840fd61ab9502b3d3036bd747 (2_10_0)
 CVE-2021-32273 (An issue was discovered in faad2 through 2.10.0. A stack-buffer-overfl ...)
 	- faad2 2.10.0-1
+	[stretch] - faad2 <not-affected> (Vulnerable code not present, introduced in 2.8.2)
 	NOTE: https://github.com/knik0/faad2/issues/56
 	NOTE: https://github.com/knik0/faad2/commit/1073aeef823cafd844704389e9a497c257768e2f (2_10_0)
 CVE-2021-32272 (An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow ...)
 	- faad2 2.10.0-1
+	[stretch] - faad2 <not-affected> (Vulnerable code not present, introduced in 2.8.2)
 	NOTE: https://github.com/knik0/faad2/issues/57
 	NOTE: https://github.com/knik0/faad2/commit/1b71a6ba963d131375f5e489b3b25e36f19f3f24 (2_10_0)
 CVE-2021-32271 (An issue was discovered in gpac through 20200801. A stack-buffer-overf ...)


=====================================
data/dla-needed.txt
=====================================
@@ -50,6 +50,8 @@ linux (Ben Hutchings)
 --
 linux-4.19 (Ben Hutchings)
 --
+mailman
+--
 mosquitto (Anton Gladky)
   NOTE: 20210805: coordinating upload to buster before DLA for Stretch (codehelp)
   NOTE: 20210806: CVE-2021-34432 ignored in buster and stretch. Vulnerable code not accessible. (codehelp)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/beb2ab04d6ef3be0c69446e9e2c552433dfd9369...9828912313f9b8c7fd5822e24bad83edc33574f2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/beb2ab04d6ef3be0c69446e9e2c552433dfd9369...9828912313f9b8c7fd5822e24bad83edc33574f2
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211022/82acf233/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list