[Git][security-tracker-team/security-tracker][master] Reserve DLA-3682-1 for ncurses

Guilhem Moulin (@guilhem) guilhem at debian.org
Sun Dec 3 18:09:21 GMT 2023



Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7e3030b5 by Guilhem Moulin at 2023-12-03T19:08:48+01:00
Reserve DLA-3682-1 for ncurses

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -34185,7 +34185,6 @@ CVE-2023-29492 (Novi Survey before 8.9.43676 allows remote attackers to execute
 CVE-2023-29491 (ncurses before 6.4 20230408, when used by a setuid application, allows ...)
 	- ncurses 6.4-3 (bug #1034372)
 	[bullseye] - ncurses 6.2+20201114-2+deb11u2
-	[buster] - ncurses <no-dsa> (Minor issue)
 	NOTE: https://invisible-island.net/ncurses/NEWS.html#index-t20230408
 	NOTE: http://ncurses.scripts.mit.edu/?p=ncurses.git;a=commitdiff;h=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56
 	NOTE: https://github.com/ThomasDickey/ncurses-snapshots/commit/a6d3f92bb5bba1a71c7c3df39497abbe5fe999ff


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[03 Dec 2023] DLA-3682-1 ncurses - security update
+	{CVE-2021-39537 CVE-2023-29491}
+	[buster] - ncurses 6.1+20181013-2+deb10u5
 [03 Dec 2023] DLA-3681-1 amanda - security update
 	{CVE-2022-37703 CVE-2022-37705 CVE-2023-30577}
 	[buster] - amanda 1:3.5.1-2+deb10u2


=====================================
data/dla-needed.txt
=====================================
@@ -110,10 +110,6 @@ linux-5.10
 mariadb-10.3
   NOTE: 20231129: Added by Front-Desk (Beuc)
 --
-ncurses (guilhem)
-  NOTE: 20231201: Added by Front-Desk (Beuc)
-  NOTE: 20231201: Follow fixes from bullseye 11.8 (1 CVE) (Beuc/front-desk)
---
 netatalk (gladk)
   NOTE: 20231119: Added by Front-Desk (apo)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e3030b572104847e2b72582d117e4c67f1ff3ef

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e3030b572104847e2b72582d117e4c67f1ff3ef
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231203/630ca381/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list