[Git][security-tracker-team/security-tracker][master] Reserve DLA-3028-1 for atftp

Thorsten Alteholz (@alteholz) alteholz at debian.org
Fri May 27 00:33:55 BST 2022



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
560804eb by Thorsten Alteholz at 2022-05-27T01:33:36+02:00
Reserve DLA-3028-1 for atftp

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -20829,7 +20829,6 @@ CVE-2021-46671 (options.c in atftp before 0.7.5 reads past the end of an array,
 	- atftp 0.7.git20210915-1 (bug #1004974)
 	[bullseye] - atftp 0.7.git20120829-3.3+deb11u2
 	[buster] - atftp 0.7.git20120829-3.2~deb10u3
-	[stretch] - atftp <no-dsa> (Minor issue)
 	NOTE: https://sourceforge.net/p/atftp/code/ci/9cf799c40738722001552618518279e9f0ef62e5 (v0.7.5)
 CVE-2022-24407 (In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does  ...)
 	{DSA-5087-1 DLA-2931-1}


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[27 May 2022] DLA-3028-1 atftp - security update
+	{CVE-2021-46671}
+	[stretch] - atftp 0.7.git20120829-3.1~deb9u3
 [26 May 2022] DLA-3027-1 neutron - security update
 	{CVE-2021-40085}
 	[stretch] - neutron 2:9.1.1-3+deb9u3


=====================================
data/dla-needed.txt
=====================================
@@ -22,9 +22,6 @@ amd64-microcode
 asterisk (Abhijith PA)
   NOTE: 20220424: programming language C
 --
-atftp (Thorste Alteholz)
-  NOTE: 20220523: Harmonize with Debian 10.12 (1 CVE) (Beuc/front-desk)
---
 avahi
   NOTE: 20220523: Harmonize with Debian 10.9 (1 Debian-specific CVE) (Beuc/front-desk)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/560804eb3641bf21604ac48ce76341ee6e0ec49a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/560804eb3641bf21604ac48ce76341ee6e0ec49a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220526/5a42f14c/attachment.htm>


More information about the debian-security-tracker-commits mailing list