[Git][security-tracker-team/security-tracker][master] dla: drop libarchive

Sylvain Beucler (@beuc) beuc at debian.org
Fri Dec 2 09:31:06 GMT 2022



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
680465e8 by Sylvain Beucler at 2022-12-02T10:30:17+01:00
dla: drop libarchive
Last DLA was uploaded only last week, there's only one minor CVE, and bullseye won't fix it now
A future FD will add it back when there are new CVEs, or a bullseye fix that will show up in lts-cve-triage.py

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -30065,6 +30065,7 @@ CVE-2022-36228
 CVE-2022-36227 (In libarchive 3.6.1, the software does not check for an error after ca ...)
 	- libarchive <unfixed> (bug #1024669)
 	[bullseye] - libarchive <no-dsa> (Minor issue)
+	[buster] - libarchive <postponed> (Minor issue, clean crash, follow bullseye updates)
 	NOTE: https://github.com/libarchive/libarchive/issues/1754
 	NOTE: https://github.com/libarchive/libarchive/pull/1759
 	NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/bff38efe8c110469c5080d387bec62a6ca15b1a5


=====================================
data/dla-needed.txt
=====================================
@@ -108,10 +108,6 @@ lava
 libapreq2
   NOTE: 20221031: Programming language: C.
 --
-libarchive
-  NOTE: 20221128: Programming language: C.
-  NOTE: 20221128: VCS: https://salsa.debian.org/lts-team/packages/libarchive.git
---
 libcommons-jxpath-java
   NOTE: 20221027: Programming language: Java.
   NOTE: 20221027: Maintainer notes: Wait for the outcome of upstream discussion. See CVE-2022-41852 for pull requests.



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/680465e84cef049390d402f516625e9874a4af95

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/680465e84cef049390d402f516625e9874a4af95
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221202/478e9f38/attachment.htm>


More information about the debian-security-tracker-commits mailing list