[Git][security-tracker-team/security-tracker][master] 4 commits: mark CVE-2021-41043 as no-dsa for Stretch
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Sat Jan 22 00:25:19 GMT 2022
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
66eb9963 by Thorsten Alteholz at 2022-01-22T00:58:18+01:00
mark CVE-2021-41043 as no-dsa for Stretch
- - - - -
6d0eae4f by Thorsten Alteholz at 2022-01-22T01:00:44+01:00
mark CVE-2021-40874 as no-dsa for Stretch
- - - - -
498703fe by Thorsten Alteholz at 2022-01-22T01:17:05+01:00
add ipython
- - - - -
abe96cde by Thorsten Alteholz at 2022-01-22T01:21:41+01:00
add ujson
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -22212,6 +22212,7 @@ CVE-2021-41043 (Use after free in tcpslice triggers AddressSanitizer, no other c
- tcpslice <unfixed> (bug #1003190)
[bullseye] - tcpslice <no-dsa> (Minor issue)
[buster] - tcpslice <no-dsa> (Minor issue)
+ [stretch] - tcpslice <no-dsa> (Minor issue)
NOTE: https://github.com/the-tcpdump-group/tcpslice/issues/11
NOTE: https://github.com/the-tcpdump-group/tcpslice/commit/030859fce9c77417de657b9bb29c0f78c2d68f4a (tcpslice-1.5)
CVE-2021-41042
@@ -22582,6 +22583,7 @@ CVE-2021-40874 [RESTServer pwdConfirm always returns true with Combination + Ker
- lemonldap-ng <unfixed>
[bullseye] - lemonldap-ng <no-dsa> (Minor issue)
[buster] - lemonldap-ng <no-dsa> (Minor issue)
+ [stretch] - lemonldap-ng <no-dsa> (Minor issue)
NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2612
NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/66946e8f754812b375768c2124937137c856fe0c
CVE-2021-40873 (An issue was discovered in Softing Industrial Automation OPC UA C++ SD ...)
=====================================
data/dla-needed.txt
=====================================
@@ -58,6 +58,8 @@ gpac (Roberto C. Sánchez)
guacamole-client
NOTE: 20220114: package unmaintained AFAICS and only present in stretch (Beuc)
--
+ipython
+--
libarchive (Thorsten Alteholz)
NOTE: 20220102: testing package
NOTE: 20220116: waiting for upload in higher releases
@@ -109,6 +111,9 @@ samba (Utkarsh Gupta)
NOTE: 20211212: Fix is too large, coordination with ELTS-upload
NOTE: 20220110: fix applied, but will need a second opinion. (utkarsh)
--
+ujson
+ NOTE: 20220121: please reheck, at least the mentioned function is available in Stretch
+--
vim (Emilio)
--
zabbix
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/96456572dabf2fb0910608d0c82fa0785155a3c5...abe96cde0646362e316a689589fef811c0213023
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/96456572dabf2fb0910608d0c82fa0785155a3c5...abe96cde0646362e316a689589fef811c0213023
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220122/0593392a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list