[Git][security-tracker-team/security-tracker][master] 4 commits: mark CVE-2021-41043 as no-dsa for Stretch

Thorsten Alteholz (@alteholz) alteholz at debian.org
Sat Jan 22 00:25:19 GMT 2022



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
66eb9963 by Thorsten Alteholz at 2022-01-22T00:58:18+01:00
mark CVE-2021-41043 as no-dsa for Stretch

- - - - -
6d0eae4f by Thorsten Alteholz at 2022-01-22T01:00:44+01:00
mark CVE-2021-40874 as no-dsa for Stretch

- - - - -
498703fe by Thorsten Alteholz at 2022-01-22T01:17:05+01:00
add ipython

- - - - -
abe96cde by Thorsten Alteholz at 2022-01-22T01:21:41+01:00
add ujson

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -22212,6 +22212,7 @@ CVE-2021-41043 (Use after free in tcpslice triggers AddressSanitizer, no other c
 	- tcpslice <unfixed> (bug #1003190)
 	[bullseye] - tcpslice <no-dsa> (Minor issue)
 	[buster] - tcpslice <no-dsa> (Minor issue)
+	[stretch] - tcpslice <no-dsa> (Minor issue)
 	NOTE: https://github.com/the-tcpdump-group/tcpslice/issues/11
 	NOTE: https://github.com/the-tcpdump-group/tcpslice/commit/030859fce9c77417de657b9bb29c0f78c2d68f4a (tcpslice-1.5)
 CVE-2021-41042
@@ -22582,6 +22583,7 @@ CVE-2021-40874 [RESTServer pwdConfirm always returns true with Combination + Ker
 	- lemonldap-ng <unfixed>
 	[bullseye] - lemonldap-ng <no-dsa> (Minor issue)
 	[buster] - lemonldap-ng <no-dsa> (Minor issue)
+	[stretch] - lemonldap-ng <no-dsa> (Minor issue)
 	NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2612
 	NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/66946e8f754812b375768c2124937137c856fe0c
 CVE-2021-40873 (An issue was discovered in Softing Industrial Automation OPC UA C++ SD ...)


=====================================
data/dla-needed.txt
=====================================
@@ -58,6 +58,8 @@ gpac (Roberto C. Sánchez)
 guacamole-client
   NOTE: 20220114: package unmaintained AFAICS and only present in stretch (Beuc)
 --
+ipython
+--
 libarchive (Thorsten Alteholz)
   NOTE: 20220102: testing package
   NOTE: 20220116: waiting for upload in higher releases
@@ -109,6 +111,9 @@ samba (Utkarsh Gupta)
   NOTE: 20211212: Fix is too large, coordination with ELTS-upload
   NOTE: 20220110: fix applied, but will need a second opinion. (utkarsh)
 --
+ujson
+  NOTE: 20220121: please reheck, at least the mentioned function is available in Stretch
+--
 vim (Emilio)
 --
 zabbix



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/96456572dabf2fb0910608d0c82fa0785155a3c5...abe96cde0646362e316a689589fef811c0213023

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/96456572dabf2fb0910608d0c82fa0785155a3c5...abe96cde0646362e316a689589fef811c0213023
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220122/0593392a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list