[Git][security-tracker-team/security-tracker][master] 2 commits: Reserve DSA-5315-1 libxstream-java

Markus Koschany (@apo) apo at debian.org
Wed Jan 11 22:25:56 GMT 2023



Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
179ca9bd by Markus Koschany at 2023-01-11T23:23:33+01:00
Reserve DSA-5315-1 libxstream-java

- - - - -
a3c975ce by Markus Koschany at 2023-01-11T23:24:43+01:00
Reserve DSA-5316-1 netty

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -90449,7 +90449,6 @@ CVE-2021-43798 (Grafana is an open-source platform for monitoring and observabil
 	- grafana <removed>
 CVE-2021-43797 (Netty is an asynchronous event-driven network application framework fo ...)
 	- netty 1:4.1.48-6 (bug #1001437)
-	[bullseye] - netty <no-dsa> (Minor issue)
 	[buster] - netty <no-dsa> (Minor issue)
 	[stretch] - netty <no-dsa> (Minor issue)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-wx5j-54mm-rqqq
@@ -110931,14 +110930,12 @@ CVE-2021-37138
 	RESERVED
 CVE-2021-37137 (The Snappy frame decoder function doesn't restrict the chunk length wh ...)
 	- netty 1:4.1.48-6 (bug #1014769)
-	[bullseye] - netty <no-dsa> (Minor issue)
 	[buster] - netty <no-dsa> (Minor issue)
 	[stretch] - netty <no-dsa> (Minor issue)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-9vjp-v76f-g363
 	NOTE: Fixed by: https://github.com/netty/netty/commit/6da4956b31023ae967451e1d94ff51a746a9194f (netty-4.1.68.Final)
 CVE-2021-37136 (The Bzip2 decompression decoder function doesn't allow setting size re ...)
 	- netty 1:4.1.48-6 (bug #1014769)
-	[bullseye] - netty <no-dsa> (Minor issue)
 	[buster] - netty <no-dsa> (Minor issue)
 	[stretch] - netty <no-dsa> (Minor issue)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,9 @@
+[11 Jan 2023] DSA-5316-1 netty - security update
+	{CVE-2021-37136 CVE-2021-37137 CVE-2021-43797 CVE-2022-41881 CVE-2022-41915}
+	[bullseye] - netty 1:4.1.48-4+deb11u1
+[11 Jan 2023] DSA-5315-1 libxstream-java - security update
+	{CVE-2022-41966}
+	[bullseye] - libxstream-java 1.4.15-3+deb11u2
 [11 Jan 2023] DSA-5314-1 emacs - security update
 	{CVE-2022-45939}
 	[bullseye] - emacs 1:27.1+1-3.1+deb11u1


=====================================
data/dsa-needed.txt
=====================================
@@ -20,8 +20,6 @@ frr
 lava
   Maintainer will prepare updates
 --
-libxstream-java (apo)
---
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
   releases to more recent v5.10.y versions



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1b7f651ab74ba250f51e8b972869f25dd3197d82...a3c975ce4d295451ae4ab4cc28961407abbe4465

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1b7f651ab74ba250f51e8b972869f25dd3197d82...a3c975ce4d295451ae4ab4cc28961407abbe4465
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230111/78a8d4a9/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list