[Git][security-tracker-team/security-tracker][master] 3 commits: mark CVE-2021-32272 as not-affected for Stretch
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Fri Oct 22 23:14:49 BST 2021
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1458892d by Thorsten Alteholz at 2021-10-22T23:48:42+02:00
mark CVE-2021-32272 as not-affected for Stretch
- - - - -
b7b3e59f by Thorsten Alteholz at 2021-10-22T23:48:43+02:00
mark CVE-2021-32273 as not-affected for Stretch
- - - - -
98289123 by Thorsten Alteholz at 2021-10-23T00:13:12+02:00
add mailman
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -26243,10 +26243,12 @@ CVE-2021-32274 (An issue was discovered in faad2 through 2.10.0. A heap-buffer-o
NOTE: https://github.com/knik0/faad2/commit/c78251b2b5d41ea840fd61ab9502b3d3036bd747 (2_10_0)
CVE-2021-32273 (An issue was discovered in faad2 through 2.10.0. A stack-buffer-overfl ...)
- faad2 2.10.0-1
+ [stretch] - faad2 <not-affected> (Vulnerable code not present, introduced in 2.8.2)
NOTE: https://github.com/knik0/faad2/issues/56
NOTE: https://github.com/knik0/faad2/commit/1073aeef823cafd844704389e9a497c257768e2f (2_10_0)
CVE-2021-32272 (An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow ...)
- faad2 2.10.0-1
+ [stretch] - faad2 <not-affected> (Vulnerable code not present, introduced in 2.8.2)
NOTE: https://github.com/knik0/faad2/issues/57
NOTE: https://github.com/knik0/faad2/commit/1b71a6ba963d131375f5e489b3b25e36f19f3f24 (2_10_0)
CVE-2021-32271 (An issue was discovered in gpac through 20200801. A stack-buffer-overf ...)
=====================================
data/dla-needed.txt
=====================================
@@ -50,6 +50,8 @@ linux (Ben Hutchings)
--
linux-4.19 (Ben Hutchings)
--
+mailman
+--
mosquitto (Anton Gladky)
NOTE: 20210805: coordinating upload to buster before DLA for Stretch (codehelp)
NOTE: 20210806: CVE-2021-34432 ignored in buster and stretch. Vulnerable code not accessible. (codehelp)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/beb2ab04d6ef3be0c69446e9e2c552433dfd9369...9828912313f9b8c7fd5822e24bad83edc33574f2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/beb2ab04d6ef3be0c69446e9e2c552433dfd9369...9828912313f9b8c7fd5822e24bad83edc33574f2
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211022/82acf233/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list