[Git][security-tracker-team/security-tracker][master] Reserve DLA-2876-1 for vim
Anton Gladky (@gladk)
gladk at debian.org
Mon Jan 10 21:11:57 GMT 2022
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4e874c58 by Anton Gladky at 2022-01-10T22:11:39+01:00
Reserve DLA-2876-1 for vim
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -19742,7 +19742,6 @@ CVE-2021-3796 (vim is vulnerable to Use After Free ...)
- vim 2:8.2.3455-1 (bug #994497)
[bullseye] - vim 2:8.2.2434-3+deb11u1
[buster] - vim <no-dsa> (Minor issue)
- [stretch] - vim <no-dsa> (Minor issue)
NOTE: https://huntr.dev/bounties/ab60b7f3-6fb1-4ac2-a4fa-4d592e08008d/
NOTE: https://github.com/vim/vim/commit/35a9a00afcb20897d462a766793ff45534810dc3 (v8.2.3428)
NOTE: https://www.openwall.com/lists/oss-security/2021/10/01/1
@@ -20197,7 +20196,6 @@ CVE-2021-3778 (vim is vulnerable to Heap-based Buffer Overflow ...)
- vim 2:8.2.3455-1 (bug #994498)
[bullseye] - vim 2:8.2.2434-3+deb11u1
[buster] - vim <no-dsa> (Minor issue)
- [stretch] - vim <no-dsa> (Minor issue)
NOTE: https://huntr.dev/bounties/d9c17308-2c99-4f9f-a706-f7f72c24c273
NOTE: https://github.com/vim/vim/commit/65b605665997fad54ef39a93199e305af2fe4d7f (v8.2.3409)
NOTE: https://www.openwall.com/lists/oss-security/2021/10/01/1
@@ -116744,7 +116742,6 @@ CVE-2019-20808 (In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI V
CVE-2019-20807 (In Vim before 8.1.0881, users can circumvent the rvim restricted mode ...)
- vim 2:8.1.2136-1
[buster] - vim <no-dsa> (Minor issue)
- [stretch] - vim <no-dsa> (Minor issue)
[jessie] - vim <no-dsa> (Minor issue)
NOTE: https://github.com/vim/vim/commit/8c62a08faf89663e5633dc5036cd8695c80f1075
CVE-2020-13644 (An issue was discovered in the Accordion plugin before 2.2.9 for WordP ...)
@@ -263627,7 +263624,6 @@ CVE-2017-17088 (The Enterprise version of SyncBreeze 10.2.12 and earlier is affe
CVE-2017-17087 (fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp f ...)
{DLA-1871-1}
- vim 2:8.0.1401-1
- [stretch] - vim <no-dsa> (Minor issue)
[wheezy] - vim <no-dsa> (Minor issue)
NOTE: https://github.com/vim/vim/commit/5a73e0ca54c77e067c3b12ea6f35e3e8681e8cf8 (8.0.1263)
CVE-2017-17086 (Indeo Otter through 1.7.4 mishandles a "</script>" substring in ...)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[10 Jan 2022] DLA-2876-1 vim - security update
+ {CVE-2017-17087 CVE-2019-20807 CVE-2021-3778 CVE-2021-3796}
+ [stretch] - vim 2:8.0.0197-4+deb9u4
[10 Jan 2022] DLA-2875-1 clamav - security update
[stretch] - clamav 0.103.4+dfsg-0+deb9u1
[04 Jan 2022] DLA-2874-1 thunderbird - security update
=====================================
data/dla-needed.txt
=====================================
@@ -114,13 +114,6 @@ sphinxsearch (Thorsten Alteholz)
thunderbird (Emilio)
NOTE: 20220104: ftbfs on armhf (pochu)
--
-vim (Anton)
- NOTE: 20211203: adding here as it's in the ela-needed as well
- NOTE: 20211203: so worth fixing in stretch, too. Co-ordinate w/
- NOTE: 20211203: Emilio since he's working on it for jessie. (utkarsh)
- NOTE: 20211220: WIP (Anton)
- NOTE: 20220103: Upload is planed this week (Anton)
---
wordpress (Utkarsh)
NOTE: 20220108: Issues may not warrant a DLA. See comment for commit 3ae7f35d1 re. previous release. (lamby)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e874c583c7ed5259ebbe3e1dda3976d9ed83aea
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e874c583c7ed5259ebbe3e1dda3976d9ed83aea
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220110/074a4e36/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list